CNCVE编号:CNCVE-20020088 CVE编号: 安全级别:中 漏洞中文描述: Microsoft Internet Explorer通过对showModalDialog和showModelessDialog两个函数的脚本调用来支持包含对话框。这两个函数接收URL位置作为对话框的内容,一个可选的参数变量允许数据从调用的页面传递到对话框。核查程序来确保数据传递到和调用页面相同的域中的对话框。这防止了恶意方将内容传递到任意的对话框。然而,如果提供给对话框的URL重定向到第二个位置时,只有第一个经过了安全检查。利用这一点允许恶意的内容插入到敏感的对话框中。在本地计算机环境中可以执行任意代码。 漏洞英文描述: Microsoft Internet Explorer includes support for dialog windows through script calls to the two functions showModalDialog and showModelessDialog. These functions accept a URL location for the dialog content, and an option argument parameter to allow data to be passed to the dialog from the calling page. A check is done to ensure that data is only passed to dialogs located in the same domain as the calling page. This prevents a malicious party from injecting content into arbitrary dialogs. However, if the URL provided as the dialog source redirects to a second location, only the first is subject to this security check. Exploitation may allow malicious content to be inserted into sensitive dialogs. Execution of arbitrary script within the local computer context has been demonstrated. 漏洞参考: http://online.securityfocus.com/bid/4527/info/ 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:权限有效性检查错误