Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The focus handling for the onkeydown event in Microsoft Internet Explorer 6.0 allows remote attackers to change field focus and copy keystrokes via a certain use of a JavaScript htmlFor attribute, as demonstrated by changing focus from a textarea to a file upload field, a related issue to CVE-2007-3511.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Microsoft Internet Explorer安全漏洞
Vulnerability Description
Microsoft Internet Explorer(IE)是美国微软(Microsoft)公司的一款Windows操作系统附带的Web浏览器。 Internet Explorer在处理文件上传时存在漏洞,恶意网站可能利用此漏洞窃取用户系统上的文件。 通常由于安全限制JavaScript是不允许设置焦点或在文件上传字段中设置值,以防从用户机器上传任意文件。浏览器厂商在表单的文件字段中实施这个限制,计算机用户只有选择了文件才能上传。但如果用户使用IE访问了恶意网页的话,就可能窃取用户的焦点,绕过浏览器安全
CVSS Information
N/A
Vulnerability Type
N/A