Microsoft Internet Explorer outerHTML 跨域漏洞

漏洞信息详情

Microsoft Internet Explorer outerHTML 跨域漏洞

漏洞简介

Internet Explorer是微软发布的非常流行的WEB浏览器。

Microsoft Internet Explorer中存在跨域漏洞。攻击者可以创建特制的对象标签,该标签的数据参数引用了攻击者站点的链接,而这个站点将Location HTTP首部指定为目标站点,这样就可以通过对象的outerHTML属性读取敏感信息。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

http://www.microsoft.com/technet/security/bulletin/ms06-042.mspx

参考网址

来源: US-CERT

名称: TA06-220A

链接:http://www.us-cert.gov/cas/techalerts/TA06-220A.html

来源: US-CERT

名称: VU#883108

链接:http://www.kb.cert.org/vuls/id/883108

来源: XF

名称: ie-redirection-information-disclosure(27452)

链接:http://xforce.iss.net/xforce/xfdb/27452

来源: BID

名称: 18682

链接:http://www.securityfocus.com/bid/18682

来源: BUGTRAQ

名称: 20060704 Re: Browser bugs hit IE, Firefox today (SANS)

链接:http://www.securityfocus.com/archive/1/archive/1/439146/100/0/threaded

来源: BUGTRAQ

名称: 20060630 Re: Browser bugs hit IE, Firefox today (SANS)

链接:http://www.securityfocus.com/archive/1/archive/1/438864/100/0/threaded

来源: BUGTRAQ

名称: 20060630 RE: [Full-disclosure] Browser bugs hit IE, Firefox today (SANS)

链接:http://www.securityfocus.com/archive/1/archive/1/438863/100/0/threaded

来源: BUGTRAQ

名称: 20060630 ISC: Firefox immune to outerHTML flaw in MSIE [Was: Browser bugs hit IE, Firefox]

链接:http://www.securityfocus.com/archive/1/archive/1/438811/100/0/threaded

来源: BUGTRAQ

名称: 20060630 Re: [Full-disclosure] Browser bugs hit IE, Firefox today (SANS)

链接:http://www.securityfocus.com/archive/1/archive/1/438788/100/0/threaded

来源: BUGTRAQ

名称: 20060630 Browser bugs hit IE, Firefox today (SANS)

链接:http://www.securityfocus.com/archive/1/archive/1/438785/100/0/threaded

来源: MS

名称: MS06-042

链接:http://www.microsoft.com/technet/security/bulletin/ms06-042.mspx

来源: VUPEN

名称: ADV-2006-2553

链接:http://www.frsirt.com/english/advisories/2006/2553

来源: SECTRACK

名称: 1016388

链接:http://securitytracker.com/id?1016388

来源: MISC

链接:http://secunia.com/internet_explorer_information_disclosure_vulnerability_test

来源: SECUNIA

名称: 20825

链接:http://secunia.com/advisories/20825

来源: MISC

链接:http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20060627/3d930eda/PLEBO-2006.06.16-IE_ONE_MINOR_ONE_MAJOR.obj

来源: FULLDISC

名称: 20060627 IE_ONE_MINOR_ONE_MAJOR

链接:http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/047398.html

来源: VUPEN

名称: ADV-2006-3212

链接:http://www.frsirt.com/english/advisories/2006/3212

来源: SECUNIA

名称: 21396

链接:http://secunia.com/advisories/21396

来源: US Government Resource: oval:org.mitre.oval:def:738

名称: oval:org.mitre.oval:def:738

链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:738

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享