Microsoft Internet Explorer嵌入图象URI欺骗漏洞

Microsoft Internet Explorer嵌入图象URI欺骗漏洞

漏洞ID 1107941 漏洞类型 设计错误
发布时间 2004-05-10 更新时间 2005-10-20
图片[1]-Microsoft Internet Explorer嵌入图象URI欺骗漏洞-安全小百科CVE编号 CVE-2004-0526
图片[2]-Microsoft Internet Explorer嵌入图象URI欺骗漏洞-安全小百科CNNVD-ID CNNVD-200408-064
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/24102
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200408-064
|漏洞详情
MicrosoftInternetExplorer是一款流行的WEB浏览器。MicrosoftInternetExplorer在处理部分URI连接时存在问题,远程攻击者可以利用这个漏洞隐藏URI连接中的真实内容,诱骗用户访问恶意站点。图象包含在正确格式的HREF标记中时,可隐藏URI连接中的真实内容,这个漏洞可诱骗用户访问一个非法连接而不被怀疑。攻击者可以通过提供恶意图象使的显示的URI连接指向合法信任的站点,如果没有任何怀疑的用户把鼠标移到相关的链接,可能导致他们认为链接的是信任正确的站点而被欺骗。
|漏洞EXP
source: http://www.securityfocus.com/bid/10308/info

It has been reported that Microsoft Internet Explorer is prone to a URI obfuscation weakness that may hide the true contents of a URI link. The issue occurs when an image is contained within a properly formatted HREF tag.

This weakness could be employed to trick a user into following a malicious link.

An attacker could exploit this issue by supplying a malicious image that appears to be a URI link pointing to a page designed to mimic that of a trusted site. If an unsuspecting victim were to mouseover the link in an attempt to verify the authenticity of where it references, they may be deceived into believing that the link references the actual trusted site.

<A HREF=http://www.example.com alt="http://www.example.com">
<IMG SRC="malware.gif" USEMAP="#malware" border=0
alt="http://www.example.com"></A>
<map NAME="malware" alt="http://www.example.com">
<area SHAPE=RECT COORDS="224,21" HREF="http://www.malware.com"
alt="http://www.example.com">
</MAP>
|参考资料

来源:XF
名称:ie-ahref-url-spoofing(16102)
链接:http://xforce.iss.net/xforce/xfdb/16102
来源:BID
名称:10308
链接:http://www.securityfocus.com/bid/10308
来源:www.kurczaba.com
链接:http://www.kurczaba.com/securityadvisories/0405132poc.htm
来源:BUGTRAQ
名称:20040510DEEPSEAPHISHING:InternetExplorer/OutlookExpress
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=108422905510713&w;=2
来源:BUGTRAQ
名称:20040517MicrosoftInternetExplorerImageMapURLSpoofVulnerability
链接:http://archives.neohapsis.com/archives/bugtraq/2004-05/0161.html

相关推荐: Proxytunnel Remote Format String Vulnerability

Proxytunnel Remote Format String Vulnerability 漏洞ID 1097645 漏洞类型 Input Validation Error 发布时间 2004-11-03 更新时间 2004-11-03 CVE编号 N/A …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享