Microsoft Internet Explorer...

- AV AC AU C I A
发布: 2001-12-13
修订: 2025-04-13

An issue exists in the way Microsoft Internet Explorer handles conflicting information in some HTTP headers used to describe non-HTML content. A malicious web server may provide content with misleading values in the content-type and content-disposition headers. Under some circumstances, IE will automatically download and execute arbitrary programs. This vulnerability may also be exploited through HTML formatted email. Some reports have stated that this vulnerability is still exploitable once patched under Internet Explorer 6.0, through use of the application/hta content-type value.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息