Microsoft Internet Explorer HTML格式标签URI模糊漏洞

漏洞信息详情

Microsoft Internet Explorer HTML格式标签URI模糊漏洞

漏洞简介

Microsoft Internet Explorer 6.0 SP2版本存在漏洞。远程攻击者可以借助包含指向合法站点BASE元素的网页欺骗状态栏中的合法URL和进行钓鱼攻击,该站点随后是一个具有空\”href\”变量的锚点元素,以及指向恶意URL的FROM,以及一个被修改为合法URL的INPUT提交元素。

漏洞公告

Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com .
@securityfocus.com>

参考网址

来源:US-CERT Vulnerability Note: VU#702086
名称: VU#702086
链接:http://www.kb.cert.org/vuls/id/702086

来源: XF
名称: ie-ahref-status-spoofing(17938)
链接:http://xforce.iss.net/xforce/xfdb/17938

来源: BID
名称: 11565
链接:http://www.securityfocus.com/bid/11565

来源: BUGTRAQ
名称: 20060223 Re: Internet Explorer Phishing mouseover issue
链接:http://www.securityfocus.com/archive/1/archive/1/425883/100/0/threaded

来源: BUGTRAQ
名称: 20060218 Re: Internet Explorer Phishing mouseover issue
链接:http://www.securityfocus.com/archive/1/archive/1/425386/100/0/threaded

来源: BUGTRAQ
名称: 20041030 Re: New URL spoofing bug in Microsoft Internet Explorer
链接:http://www.securityfocus.com/archive/1/379903

来源: SECUNIA
名称: 11273
链接:http://secunia.com/advisories/11273

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享