Microsoft Internet Explorer JavaScript本地文件枚举漏洞

Microsoft Internet Explorer JavaScript本地文件枚举漏洞

漏洞ID 1106558 漏洞类型 设计错误
发布时间 2002-01-03 更新时间 2005-10-20
图片[1]-Microsoft Internet Explorer JavaScript本地文件枚举漏洞-安全小百科CVE编号 CVE-2002-2031
图片[2]-Microsoft Internet Explorer JavaScript本地文件枚举漏洞-安全小百科CNNVD-ID CNNVD-200212-208
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/21199
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200212-208
|漏洞详情
InternetExplorer5.0,5.0.1和5.5版本存在漏洞。当JavaScript执行启用时,远程攻击者可以通过具有可以引用non-JavaScript文件的src参数的脚本标签确定任意文件的存在,然后使用onError事件处理器来监察结果。
|漏洞EXP
source: http://www.securityfocus.com/bid/3779/info
 
Microsoft Internet Explorer is prone to a vulnerability which may disclose sensitive information to a malicious webmaster.
 
When script code includes a file outside of the document it is embedded in and the file does not exist, the onError event handler will run script if it is enabled. This script can determine whether the file to be included exists or not. This can be used to verify the existence of files on client hosts by creating webpages that include files from the local host using 'file://'. 

https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/bin-sploits/21199.zip
|参考资料

来源:BID
名称:3779
链接:http://www.securityfocus.com/bid/3779
来源:XF
名称:ie-javascript-onerror(7784)
链接:http://www.iss.net/security_center/static/7784.php
来源:BUGTRAQ
名称:20020103SeriousIEprivacyissues
链接:http://archives.neohapsis.com/archives/bugtraq/2002-01/0019.html

相关推荐: FluxBox Xman 缓冲区溢出漏洞

FluxBox Xman 缓冲区溢出漏洞 漏洞ID 1200300 漏洞类型 缓冲区溢出 发布时间 2005-01-10 更新时间 2005-01-10 CVE编号 CVE-2004-1204 CNNVD-ID CNNVD-200501-134 漏洞平台 N/…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享