ie5.cross-frame.txt...

- AV AC AU C I A
发布: 2000-01-08
修订: 2025-04-13

Internet Explorer 5.01 under Windows 95 and 5.5 under WinNT 4.0 (suppose other versions are also vulnerable) allows circumventing "Cross frame security policy" by accessing the DOM of "old" documents using IMG SRC="javascript:..." and a design flaw in IE. This exposes the whole DOM of the target document and opens lots of security risks. This allows reading local files, reading files from any host, window spoofing, getting cookies, etc. Demonstration available here.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息