MS IE HTML Help捷径漏洞

漏洞信息详情

MS IE HTML Help捷径漏洞

漏洞简介

Internet Explorer 5.x版本的window.showHelp()方法无法限制从本地主机执行HTML help文件(.chm)。远程攻击者借助Microsoft Networking可以执行任意命令。

漏洞公告

Microsoft has released the following patches to address this vulnerability. According to CERT/CC, the patch does not fully address all circumstances in which the vulnerability can be exploited. Please see
http://www.cert.org/advisories/CA-2000-12.html for more details. The physical path disclosure detailed in the update under ‘Discussion’ is not addressed by this issue.
Microsoft Internet Explorer 4.0 for Windows NT 4.0

Microsoft Internet Explorer 4.0

Microsoft Internet Explorer 4.0 for Windows 95

Microsoft Internet Explorer 4.0.1 for Windows NT 4.0

Microsoft Internet Explorer 4.0.1

Microsoft Internet Explorer 5.0 for Windows 95

Microsoft Internet Explorer 5.0 for Windows 98

Microsoft Internet Explorer 5.0 for Windows NT 4.0

Microsoft Internet Explorer 5.0.1 for Windows 95

Microsoft Internet Explorer 5.0.1 for Windows 98

Microsoft Internet Explorer 5.0.1 for Windows 2000

Microsoft Internet Explorer 5.0.1 for Windows NT 4.0

参考网址

来源: BID
名称: 1033
链接:http://www.securityfocus.com/bid/1033

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享