漏洞信息详情
Microsoft Internet Explorer HTML格式标签URI模糊漏洞
- CNNVD编号:CNNVD-200412-327
- 危害等级: 高危
- CVE编号:
CVE-2004-1104
- 漏洞类型:
其他
- 发布时间:
2004-12-31
- 威胁类型:
远程
- 更新时间:
2006-06-15
- 厂 商:
microsoft - 漏洞来源:
disclosed this weakness.’);”>”http-equiv@excite… -
漏洞简介
Microsoft Internet Explorer 6.0 SP2版本存在漏洞。远程攻击者可以借助包含指向合法站点BASE元素的网页欺骗状态栏中的合法URL和进行钓鱼攻击,该站点随后是一个具有空\”href\”变量的锚点元素,以及指向恶意URL的FROM,以及一个被修改为合法URL的INPUT提交元素。
漏洞公告
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com
参考网址
来源:US-CERT Vulnerability Note: VU#702086
名称: VU#702086
链接:http://www.kb.cert.org/vuls/id/702086
来源: XF
名称: ie-ahref-status-spoofing(17938)
链接:http://xforce.iss.net/xforce/xfdb/17938
来源: BID
名称: 11565
链接:http://www.securityfocus.com/bid/11565
来源: BUGTRAQ
名称: 20060223 Re: Internet Explorer Phishing mouseover issue
链接:http://www.securityfocus.com/archive/1/archive/1/425883/100/0/threaded
来源: BUGTRAQ
名称: 20060218 Re: Internet Explorer Phishing mouseover issue
链接:http://www.securityfocus.com/archive/1/archive/1/425386/100/0/threaded
来源: BUGTRAQ
名称: 20041030 Re: New URL spoofing bug in Microsoft Internet Explorer
链接:http://www.securityfocus.com/archive/1/379903
来源: SECUNIA
名称: 11273
链接:http://secunia.com/advisories/11273