漏洞信息详情
微软IE和OE执行XML样式表中的活动脚本的漏洞
- CNNVD编号:CNNVD-200104-016
- 危害等级: 高危
- CVE编号:
CVE-2001-1325
- 漏洞类型:
输入验证
- 发布时间:
2001-04-20
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
microsoft - 漏洞来源:
-
漏洞简介
CVE(CAN) ID: CAN-2001-1325
Internet Explorer和Outlook Express在处理XML样式表时存在一个漏洞。尽管所有安全区域中的活动脚本都被禁止,但是IE和OE仍然允许执行包含在XML页面的样式表中的脚本。
<* 来源:Georgi Guninski (guninski@guninski.com)*>
漏洞公告
厂商补丁:
微软早先提供的用于Windows Script Host的补丁也可以用于本漏洞:
Microsoft Internet Explorer 5.5:
Microsoft patch ste51en
http://www.microsoft.com/scripting/downloads/v51/other/ste51en.exe
Windows 95, 98, NT 4.0
Microsoft patch scripten
http://www.microsoft.com/scripting/downloads/v51/windows2000/scripten.exe
Windows 2000
Microsoft patch scr55en
http://www.microsoft.com/scripting/downloads/v55/other/scr55en.exe
Microsoft Internet Explorer 5.0:
Microsoft patch ste51en
http://www.microsoft.com/scripting/downloads/v51/other/ste51en.exe
Windows 95, 98, NT 4.0
Microsoft patch scripten
http://www.microsoft.com/scripting/downloads/v51/windows2000/scripten.exe
Windows 2000
Microsoft patch scr55en
http://www.microsoft.com/scripting/downloads/v55/other/scr55en.exe
Microsoft Outlook Express 5.5:
Microsoft patch scr55en
http://www.microsoft.com/scripting/downloads/v55/other/scr55en.exe
Windows 95, 98, NT 4.0
Microsoft patch scripten
http://www.microsoft.com/scripting/downloads/v51/windows2000/scripten.exe
Windows 2000
Microsoft patch ste51en
http://www.microsoft.com/scripting/downloads/v51/other/ste51en.exe
Microsoft Outlook Express 5.0:
Microsoft patch ste51en
http://www.microsoft.com/scripting/downloads/v51/other/ste51en.exe
Windows 95, 98, NT 4.0
Microsoft patch scripten
http://www.microsoft.com/scripting/downloads/v51/windows2000/scripten.exe
Windows 2000
Microsoft patch scr55en
http://www.microsoft.com/scripting/downloads/v55/other/scr55en.exe
参考网址
来源: XF
名称: ie-xml-stylesheets-scripting(6448)
链接:http://xforce.iss.net/static/6448.php
来源: BID
名称: 2633
链接:http://www.securityfocus.com/bid/2633
来源: BUGTRAQ
名称: 20010420 XML scripting in IE, Outlook Express
链接:http://www.securityfocus.com/archive/1/3AE02004.57FDF958@guninski.com