积极预防 及时发现
快速响应 力保恢复
Internet Explorer 4把一个URL中的32-bit 编号(“无点IP地址”)作为主机...
发布时间:2002-05-20 信息来源:管理员

CNCVE编号:CNCVE-19991087 CVE编号:CVE-1999-1087 安全级别:中 漏洞中文描述: Internet Explorer 4把一个URL中的32-bit 编号(“无点IP地址”)作为主机名而不是IP地址处理,这使得IE把Local Intranet Zone设置应用到由此而产生的网页中,这允许远程恶意网络服务器通过使用包含用于他们的服务程序的dotless IP地址的URL来执行未授权活动。 漏洞英文描述: Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthentication activities by using dotless IP in URL. 漏洞参考: 系统类型:其他 漏洞类型:其他