Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Microsoft Internet Explorer before 10 allows remote attackers to obtain sensitive information about the existence of files, and read certain data from files, via a UNC share pathname in the SRC attribute of a SCRIPT element, as demonstrated by reading a name-value pair from a local file via a \\127.0.0.1\C$\ sequence.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Microsoft Internet Explorer 安全漏洞
Vulnerability Description
Microsoft Internet Explorer是美国微软(Microsoft)公司发布的Windows操作系统中默认捆绑的Web浏览器。 Microsoft Internet Explorer 10之前版本中存在漏洞。通过SCRIPT元素的SRC属性中的UNC共享路径名,例如在本地文件中以\\127.0.0.1\C$\序列读取名称值对,远程攻击者利用该漏洞获取与文件是否存在有关的敏感信息,以及从文件中读取某些数据。
CVSS Information
N/A
Vulnerability Type
N/A