Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Microsoft Internet Explorer 权限许可和访问控制问题漏洞
Vulnerability Description
Microsoft Internet Explorer(IE)是美国微软(Microsoft)公司的一款Windows操作系统附带的Web浏览器。 Internet Explorer 5.01到6 SP1版本存在权限许可和访问控制问题漏洞。远程攻击者可以借助子框架中的javascript protocol URL 绕过区限制,当调用history.back (back)函数时,该漏洞被加入到历史目录并且在顶层窗口区域中执行。也称为“Travel Log Cross Domain 漏洞”。
CVSS Information
N/A
Vulnerability Type
N/A