积极预防 及时发现
快速响应 力保恢复
Internet Explorer公布了的某些版本中存在的一个漏洞。有可能将JavaScript代码...
发布时间:2002-05-13 信息来源:管理员

CNCVE编号:CNCVE-20020087 CVE编号: 安全级别:中 漏洞中文描述: Internet Explorer公布了的某些版本中存在的一个漏洞。有可能将JavaScript代码嵌入到浏览器的历史列表中并在适当的用户交互的页面上下文中执行。Internet Explorer保存javascript: URLs在浏览器历史列表中。脚本在javascript: URL中执行时,将继承上一次浏览的页面的安全性。这将破坏IE对包含在恶意配置的网页中的javascript: URLs防护。然而,用户可以使用他们浏览器上的“back”按钮来定位javascript: URL。 这将导致嵌入的脚本代码在另一个页面环境中执行。据报道IE 6.0和5.5有这样的情况.Internet Explorer的其他版本可能也有这样的漏洞,然而还没有证实。 漏洞英文描述: A vulnerability has been reported in some versions of Internet Explorer. It is possible to inject JavaScript code into the browser history list, and execute it within any page context given appropriate user interaction. Internet Explorer stores javascript: URLs in the browser history list. Script executed within the javascript: URL will inherit the security zone of the last viewed page. This provides protection against javascript: URLs included within a maliciously constructed web page. However, a user may navigate to a javascript: URL using the 'Back' button in their browser. This may result in the injected script code executing within the context of another page. This behavior has been reported in versions 6.0 and 5.5 of IE. Other versions of Internet Explorer may share this vulnerability. This has not, however, been confirmed. 漏洞参考: http://online.securityfocus.com/bid/4505/info/ 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误