Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka "HTML Sanitization Vulnerability."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Microsoft Internet Explorer ‘SafeHTML’ 组件跨站脚本漏洞
Vulnerability Description
Microsoft Internet Explorer是美国微软(Microsoft)公司发布的Windows操作系统中默认捆绑的Web浏览器。 Microsoft Internet Explorer 8和9版本,Communicator 2007 R2版本,Lync 2010和2010 Attendee版本中的toStaticHTML API(又名SafeHTML组件)中存在漏洞,该漏洞源于未正确处理事件属性和脚本。远程攻击者可利用该漏洞借助特制HTML文档导致跨站脚本(XSS)攻击。也称“HTML验证
CVSS Information
N/A
Vulnerability Type
N/A