Microsoft IE4剪贴板粘贴漏洞

Microsoft IE4剪贴板粘贴漏洞

漏洞ID 1105409 漏洞类型 访问验证错误
发布时间 1999-01-21 更新时间 2005-10-20
图片[1]-Microsoft IE4剪贴板粘贴漏洞-安全小百科CVE编号 CVE-1999-1453
图片[2]-Microsoft IE4剪贴板粘贴漏洞-安全小百科CNNVD-ID CNNVD-199902-010
漏洞平台 Windows CVSS评分 2.6
|漏洞来源
https://www.exploit-db.com/exploits/19164
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-199902-010
|漏洞详情
InternetExplorer4版本存在漏洞。远程攻击者(恶意网站操作者)通过InternetWebBrowserActiveX目标读取剪贴板中的内容。
|漏洞EXP
source: http://www.securityfocus.com/bid/215/info

The Windows clipboard contains data that has been cut or copied from various windows applications. This data can be accessed and posted to malicious web forms at web sites without the knowledge of the visiting end-user. Normally, Microsoft security prevents forms from accessing data other than what was copied from within the same application, however, a Microsoft Forms 2.0 TextBox ActiveX object can bypass these security rules.

The Forms 2.0 ActiveX object does not come with the Operating System. This control is loaded when Visual Basic 5.0, Project 98, Outlook 98, or Office 97 is installed on the host.

function GetClipBoard()
{
tb.paste(); // paste over the MS Forms 2.0 TextBox
document.forms(0).S1.value=tb.text; // moves the text to the text area box
}
|参考资料

来源:BID
名称:215
链接:http://www.securityfocus.com/bid/215
来源:NTBUGTRAQ
名称:19990222NewIE4vulnerability:theclipboardagain.
链接:http://marc.theaimsgroup.com/?l=ntbugtraq&m;=91979439932341&w;=2

相关推荐: Linksys Web Camera Software Next_file Parameter File Disclosure Vulnerability

Linksys Web Camera Software Next_file Parameter File Disclosure Vulnerability 漏洞ID 1098437 漏洞类型 Input Validation Error 发布时间 2004-0…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享