漏洞信息详情
Microsoft Internet Explorer鼠标点击劫持事件漏洞
- CNNVD编号:CNNVD-200402-024
- 危害等级: 高危
- CVE编号:
CVE-2003-0823
- 漏洞类型:
输入验证
- 发布时间:
2004-02-03
- 威胁类型:
远程
- 更新时间:
2005-10-31
- 厂 商:
microsoft - 漏洞来源:
Discovery of this … -
漏洞简介
Internet Explorer 6 SP1及其早期版本存在漏洞。远程攻击者通过调用window.moveBy method定向到拖放行为和其他windows上的鼠标点击行为,也称为HijackClick。
漏洞公告
Microsoft has released fixes for this issue.
A later variant of this issue (BID 9108) was discovered that is addressed in MS04-004. Please see BID 9108 and MS04-004 for further information.
Microsoft Internet Explorer 5.0.1 SP1
-
Microsoft Cumulative Security Update for Internet Explorer 5.01 for Windows 2000 Service Pack 2 (KB824145)For Internet Explorer 5.01 on Windows 2000 SP2
http://www.microsoft.com/downloads/details.aspx?FamilyId=221616D4-5893
-4DA4-A223-B0DE548D6D83&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer 5.01 for Windows 2000 Service Pack 3 (KB824145)For Internet Explorer 5.01 on Windows 2000 SP3
http://www.microsoft.com/downloads/details.aspx?FamilyId=F4853D8F-F66C
-4D8A-9979-3B4F540F90A8&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer 5.01 for Windows 2000 Service Pack 4 (KB824145)For Internet Explorer 5.01 on Windows 2000 SP4
http://www.microsoft.com/downloads/details.aspx?FamilyId=C15E2DB3-14E2
-43A4-A1A1-676374B66517&displaylang=en
Microsoft Internet Explorer 5.0.1 SP3
-
Microsoft Cumulative Security Update for Internet Explorer 5.01 for Windows 2000 Service Pack 2 (KB824145)For Internet Explorer 5.01 on Windows 2000 SP2
http://www.microsoft.com/downloads/details.aspx?FamilyId=221616D4-5893
-4DA4-A223-B0DE548D6D83&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer 5.01 for Windows 2000 Service Pack 3 (KB824145)For Internet Explorer 5.01 on Windows 2000 SP3
http://www.microsoft.com/downloads/details.aspx?FamilyId=F4853D8F-F66C
-4D8A-9979-3B4F540F90A8&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer 5.01 for Windows 2000 Service Pack 4 (KB824145)For Internet Explorer 5.01 on Windows 2000 SP4
http://www.microsoft.com/downloads/details.aspx?FamilyId=C15E2DB3-14E2
-43A4-A1A1-676374B66517&displaylang=en
Microsoft Internet Explorer 5.0.1
-
Microsoft Cumulative Security Update for Internet Explorer 5.01 for Windows 2000 Service Pack 2 (KB824145)For Internet Explorer 5.01 on Windows 2000 SP2
http://www.microsoft.com/downloads/details.aspx?FamilyId=221616D4-5893
-4DA4-A223-B0DE548D6D83&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer 5.01 for Windows 2000 Service Pack 3 (KB824145)For Internet Explorer 5.01 on Windows 2000 SP3
http://www.microsoft.com/downloads/details.aspx?FamilyId=F4853D8F-F66C
-4D8A-9979-3B4F540F90A8&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer 5.01 for Windows 2000 Service Pack 4 (KB824145)For Internet Explorer 5.01 on Windows 2000 SP4
http://www.microsoft.com/downloads/details.aspx?FamilyId=C15E2DB3-14E2
-43A4-A1A1-676374B66517&displaylang=en
Microsoft Internet Explorer 5.0.1 SP2
-
Microsoft Cumulative Security Update for Internet Explorer 5.01 for Windows 2000 Service Pack 2 (KB824145)For Internet Explorer 5.01 on Windows 2000 SP2
http://www.microsoft.com/downloads/details.aspx?FamilyId=221616D4-5893
-4DA4-A223-B0DE548D6D83&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer 5.01 for Windows 2000 Service Pack 3 (KB824145)For Internet Explorer 5.01 on Windows 2000 SP3
http://www.microsoft.com/downloads/details.aspx?FamilyId=F4853D8F-F66C
-4D8A-9979-3B4F540F90A8&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer 5.01 for Windows 2000 Service Pack 4 (KB824145)For Internet Explorer 5.01 on Windows 2000 SP4
http://www.microsoft.com/downloads/details.aspx?FamilyId=C15E2DB3-14E2
-43A4-A1A1-676374B66517&displaylang=en
Microsoft Internet Explorer 5.5 SP2
-
Microsoft Cumulative Security Update for Internet Explorer 5.5 Service Pack 2 (KB824145)
http://www.microsoft.com/downloads/details.aspx?FamilyId=E438AFD4-DF70
-448C-8925-1075C8BE6C5E&displaylang=en
Microsoft Internet Explorer 6.0 SP1
-
Microsoft Cumulative Security Update for Internet Explorer 6 Service Pack 1 (KB824145)
http://www.microsoft.com/downloads/details.aspx?FamilyId=9D8543E9-0E2B
-46C9-B6C6-12DE03860465&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer 6 SP1 64-bit Edition (KB824145)
http://www.microsoft.com/downloads/details.aspx?FamilyId=35F99CF5-3629
-4E0E-BF60-24845D2D20C9&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB824145)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7D0D02DD-8940
-48E0-B163-3FCDCB558F21&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 64-bit Edition (KB824145)
http://www.microsoft.com/downloads/details.aspx?FamilyId=8BEFA1EC-0C48
-4B65-989D-58B0CE1E6F95&displaylang=en
Microsoft Internet Explorer 6.0
-
Microsoft Cumulative Security Update for Internet Explorer 6 (KB824145)
http://www.microsoft.com/downloads/details.aspx?FamilyId=4C4D22F0-FBF7
-4EA6-9CC2-27D104D4198E&displaylang=en
参考网址
来源:US-CERT Vulnerability Note: VU#413886
名称: VU#413886
链接:http://www.kb.cert.org/vuls/id/413886
来源: MS
名称: MS03-048
链接:http://www.microsoft.com/technet/security/bulletin/ms03-048.asp
来源: BUGTRAQ
名称: 20030910 MSIE->HijackClick: 1+1=2
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=106322197932006&w=2
来源: BUGTRAQ
名称: 20030911 LiuDieYu’s missing files are here.
链接:http://www.securityfocus.com/archive/1/337086
来源: SECTRACK
名称: 1006036
链接:http://www.securitytracker.com/id?1006036
来源: SECUNIA
名称: 10192
链接:http://secunia.com/advisories/10192
来源: US Government Resource: oval:org.mitre.oval:def:733
名称: oval:org.mitre.oval:def:733
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:733
来源: US Government Resource: oval:org.mitre.oval:def:588
名称: oval:org.mitre.oval:def:588
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:588
来源: US Government Resource: oval:org.mitre.oval:def:372
名称: oval:org.mitre.oval:def:372
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:372
来源: US Government Resource: oval:org.mitre.oval:def:371
名称: oval:org.mitre.oval:def:371
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:371
来源: US Government Resource: oval:org.mitre.oval:def:370
名称: oval:org.mitre.oval:def:370
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:370
来源: US Government Resource: oval:org.mitre.oval:def:369
名称: oval:org.mitre.oval:def:369
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:369
来源: US Government Resource: oval:org.mitre.oval:def:368
名称: oval:org.mitre.oval:def:368
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:368