MS.IE.OuterHTML.Redirection.Handling.Information.Disclosure
- 特征库ID:
29522
- 漏洞级别:
高
- CVE ID:
2006-3280
- 建议的动作:
全部屏蔽
- 受影响的系统:
Windows
- 协议:
TCP, FTP
攻击漏洞描述
攻击企图利用Microsoft Internet Explorer中的信息泄露漏洞。该漏洞位于“outerHTML”属性中。 它可能允许攻击者在目标用户的浏览器会话的上下文中访问任意网站。 这可能允许攻击者使用被利用用户的权限在Web应用程序中执行操作或访问潜在敏感信息。
影响范围
Microsoft Internet Explorer 5.0
Microsoft Internet Explorer 5.0.1
Microsoft Internet Explorer 5.0.1 SP1
Microsoft Internet Explorer 5.0.1 SP2
Microsoft Internet Explorer 5.0.1 SP3
Microsoft Internet Explorer 5.0.1 SP4
Microsoft Internet Explorer 5.0.1 SP4
可能带来的后果
信息泄露:远程攻击者可以从易受攻击的系统获取敏感信息。
解决办法
应用供应商的最新更新。
Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 6 SP1的累积更新(KB918899)
Microsoft Windows 2000 Service Pack 4上或Microsoft Windows XP Service Pack 1上的Internet Explorer 6 Service Pack 1
http://www.microsoft.com/downloads/details.aspx