Microsoft VBScript Same Origin...

- AV AC AU C I A
发布: 2002-02-21
修订: 2025-04-13

In modern browsers, script code executing in the context of one website should not be able to access the properties of another. This is a security feature known as the 'same origin policy', and it is put in place to prevent malicious websites from interacting with and possibly stealing sensitive information from others in different windows. Microsoft Internet Explorer contains a vulnerability related to this protection in its implementation of the VBScript scripting language. It is possible for malicious VBScript code in one frame to access the properties of another frame in a different domain. The condition is due to a flaw in the calculation of domain boundaries, which attempt to group content from common domains across different frames together. Exploitation of this vulnerability may result in disclosure of sensitive information from other domains to remote attackers. Attackers may be able to obtain sensitive information from content belonging to other websites (such as...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息