Microsoft IE Same Origin Policy...

- AV AC AU C I A
发布: 2001-12-19
修订: 2025-04-13

There exists a vulnerability in Microsoft Internet Explorer that can allow for a violation of the same origin policy. In modern browsers, script code executing in the context of one website should not be able to access the properties of another. This is a security feature known as the 'same origin policy', and it is put in place to prevent malicious websites from interacting with and possibly stealing sensitive information from others in different windows. When one website ('parent') opens another website in a new window ('child') using the document.Open() method in vulnerable versions of MSIE, it is possible for script code in the parent to interact with properties of the child. This violation of the 'same origin policy' is a severe security vulnerability. There are many ways that an attacker could exploit this vulnerability. Attackers can construct websites that, for example: - Steal cookies associated with arbitrary websites. - Perform actions on different websites through...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息