Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read arbitrary local files and network shares via an applet tag with a codebase set to a "file://%00" (null character) URL.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Microsoft JVM Codebase信息泄露漏洞
Vulnerability Description
Microsoft JVM是一款使用在Win32操作环境中的Java虚拟机系统,Microsoft JVM包含在大部分Windows版本中,也既包含在大部分Internet Explorer版本中。Microsoft JVM有的时候也可以通过独立下载获得。 在applet标记中设置特殊的Codebase,可导致远程攻击者访问目标用户中的本地系统文件。 Applet标记中的Codebase可以设置为"file://%00",这会导致applet访问所有本地文件和网络共享。Applet也可以用来列出目录内容,
CVSS Information
N/A
Vulnerability Type
N/A