Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
WebKit before r51295, as used in Google Chrome before 4.0.249.78, presents a directory-listing page in response to an XMLHttpRequest for a file:/// URL that corresponds to a directory, which allows attackers to obtain sensitive information or possibly have unspecified other impact via a crafted local HTML document.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apple WebKit XMLHttpRequest请求响应信息泄露漏洞
Vulnerability Description
WebKit 是一个开源浏览器网页排版引擎,与之相应的引擎有Gecko(Mozilla,Firefox 等使用的排版引擎)和Trident(也称为MSHTML,IE 使用的排版引擎)。 WebKit在Google Chrome中使用时,XMLHttpRequest请求响应存在信息泄露漏洞。在相应路径file:/// URL的XMLHttpRequest请求的响应中呈现目录列表页,远程攻击者可以通过伪造本地HTML文档,获取敏感信息,导致其他未明影响。
CVSS Information
N/A
Vulnerability Type
N/A