漏洞信息详情
Microsoft Internet Explorer 5.01和 Access 2000 / 97 VBA代码执行漏洞
- CNNVD编号:CNNVD-200006-106
- 危害等级: 高危
- CVE编号:
CVE-2000-0596
- 漏洞类型:
边界条件错误
- 发布时间:
2000-06-27
- 威胁类型:
远程
- 更新时间:
2005-10-12
- 厂 商:
microsoft - 漏洞来源:
Posted to Bugtraq … -
漏洞简介
Internet Explorer 5.x版本开启Microsoft Access数据库文件文件之前无法警告用户,该文件引用于HTML文件ActiveX OBJECT标签。远程攻击者利用此漏洞可以执行任意文件,又称为\”IE Script\”漏洞。
漏洞公告
Microsoft has released the following patch which eliminates the vulnerability. It is available for download at the following location:
http://www.microsoft.com/windows/ie/download/critical/patch11.htm
参考网址
来源:CERT/CC Advisory: CA-2000-16
名称: CA-2000-16
链接:http://www.cert.org/advisories/CA-2000-16.html
来源: BUGTRAQ
名称: 20000627 IE 5 and Access 2000 vulnerability – executing programs
链接:http://www.securityfocus.com/templates/archive.pike?list=1&msg=39589359.762392DB@nat.bg
来源: MS
名称: MS00-049
链接:http://www.microsoft.com/technet/security/bulletin/MS00-049.asp
来源: BUGTRAQ
名称: 20000627 FW: IE 5 and Access 2000 vulnerability – executing programs
链接:http://www.securityfocus.com/templates/archive.pike?list=1&msg=000d01bfe0fb$418f59b0$96217aa8@src.bu.edu
来源: BID
名称: 1398
链接:http://www.securityfocus.com/bid/1398