ie-iframe.txt...

- AV AC AU C I A
发布: 2000-06-07
修订: 2025-04-13

Georgi Guninski security advisory #12 - Internet Explorer 5.01 under Windows 98 (other versions are also vulnerable) allows circumventing "Cross frame security policy" by accessing the DOM of documents using JavaScript, IFRAME and WebBrowser control. This exposes the whole DOM of the target document and opens lots of security risks, such as reading local files, reading files from any host, window spoofing, getting cookies, etc. Exploit code included. Demonstration available here.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息