Microsoft Internet Explorer鼠标点击劫持事件漏洞

漏洞信息详情

Microsoft Internet Explorer鼠标点击劫持事件漏洞

漏洞简介

Internet Explorer 6 SP1及其早期版本存在漏洞。远程攻击者通过调用window.moveBy method定向到拖放行为和其他windows上的鼠标点击行为,也称为HijackClick。

漏洞公告

Microsoft has released fixes for this issue.
A later variant of this issue (BID 9108) was discovered that is addressed in MS04-004. Please see BID 9108 and MS04-004 for further information.
Microsoft Internet Explorer 5.0.1 SP1

Microsoft Internet Explorer 5.0.1 SP3

Microsoft Internet Explorer 5.0.1

Microsoft Internet Explorer 5.0.1 SP2

Microsoft Internet Explorer 5.5 SP2

Microsoft Internet Explorer 6.0 SP1

Microsoft Internet Explorer 6.0

参考网址

来源:US-CERT Vulnerability Note: VU#413886
名称: VU#413886
链接:http://www.kb.cert.org/vuls/id/413886

来源: MS
名称: MS03-048
链接:http://www.microsoft.com/technet/security/bulletin/ms03-048.asp

来源: BUGTRAQ
名称: 20030910 MSIE->HijackClick: 1+1=2
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=106322197932006&w=2

来源: BUGTRAQ
名称: 20030911 LiuDieYu’s missing files are here.
链接:http://www.securityfocus.com/archive/1/337086

来源: SECTRACK
名称: 1006036
链接:http://www.securitytracker.com/id?1006036

来源: SECUNIA
名称: 10192
链接:http://secunia.com/advisories/10192

来源: US Government Resource: oval:org.mitre.oval:def:733
名称: oval:org.mitre.oval:def:733
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:733

来源: US Government Resource: oval:org.mitre.oval:def:588
名称: oval:org.mitre.oval:def:588
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:588

来源: US Government Resource: oval:org.mitre.oval:def:372
名称: oval:org.mitre.oval:def:372
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:372

来源: US Government Resource: oval:org.mitre.oval:def:371
名称: oval:org.mitre.oval:def:371
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:371

来源: US Government Resource: oval:org.mitre.oval:def:370
名称: oval:org.mitre.oval:def:370
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:370

来源: US Government Resource: oval:org.mitre.oval:def:369
名称: oval:org.mitre.oval:def:369
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:369

来源: US Government Resource: oval:org.mitre.oval:def:368
名称: oval:org.mitre.oval:def:368
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:368

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享