漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
漏洞
N/A
漏洞信息
Microsoft Internet Explorer 9 and earlier does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing an http: URL that redirects to a file: URL, as demonstrated by a Facebook game, related to a "cookiejacking" issue, aka "Drag and Drop Information Disclosure Vulnerability." NOTE: this vulnerability exists because of an incomplete fix in the Internet Explorer 9 release.
漏洞信息
N/A
漏洞
N/A
漏洞
Microsoft Internet Explorer输入验证错误漏洞
漏洞信息
Microsoft Internet Explorer是美国微软(Microsoft)公司发布的Windows操作系统中默认捆绑的Web浏览器。 Microsoft Internet Explorer 9及之前版本没有正确限制跨域拖放操作。用户协助的远程攻击者可以借助涉及带有SRC属性(包含一个重定向到file:URL的http:URL)的IFRAME元素的向量,读取cookie文件。
漏洞信息
N/A
漏洞
N/A