积极预防 及时发现
快速响应 力保恢复
在现代浏览器中,一个Web站点上下文执行的脚本不应该可以能够访问到其他站点的相关实体。这个安全功能称...
发布时间:2002-03-11 信息来源:管理员

CNCVE编号:CNCVE-20020029 CVE编号:CAN-2002-0052 安全级别:低 漏洞中文描述: 在现代浏览器中,一个Web站点上下文执行的脚本不应该可以能够访问到其他站点的相关实体。这个安全功能称为“同源策略”,这可以使恶意网页不能窃取其它不同窗口中的敏感信息。Microsoft IE的VBScript实现上存在一个漏洞,违背了同源策略,可能导致用户敏感信息泄露。恶意的VBScript可能利用IE访问到其它站点或域的帧(frame)中的内容,这可能是因为是计算域边界的时候出现了问题,IE试图跨不同的帧对一般域中的内容进行分组。攻击者可能借这个漏洞得到用户与其他站点会话的信息(包括用户名、口令等信息)或者传输用户文件到攻击者控制的网站。 漏洞英文描述: In modern browsers, script code executing in the context of one website should not be able to access the properties of another. This is a security feature known as the 'same origin policy', and it is put in place to prevent malicious websites from interacting with and possibly stealing sensitive information from others in different windows. Microsoft Internet Explorer contains a vulnerability related to this protection in its implementation of the VBScript scripting language. It is possible for malicious VBScript code in one frame to access the properties of another frame in a different domain. The condition is due to a flaw in the calculation of domain boundaries, which attempt to group content from common domains across different frames together. Exploitation of this vulnerability may result in disclosure of sensitive information from other domains to remote attackers. Attackers may be able to obtain sensitive information from content belonging to other websites (such as usernames, passwords, etc). It is also possible to for attackers to read the contents of files on client systems if the complete path to the file is known. This is similar to the issue described in the Vulnerability Database record for Bugtraq ID 3721, but due to a separate code flaw. 漏洞参考: http://www.microsoft.com/technet/security/bulletin/MS02-009.asp 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:其他