Anfälligkeitssuche        Suche in 187964 CVE Beschreibungen
und 85075 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.803305
Kategorie:Windows
Titel:MS IE Information Disclosure and Web Site Spoofing Vulnerabilities
Zusammenfassung:This host is installed with Microsoft Internet Explorer and is; prone to information disclosure and web site spoofing vulnerabilities.
Beschreibung:Summary:
This host is installed with Microsoft Internet Explorer and is
prone to information disclosure and web site spoofing vulnerabilities.

Vulnerability Insight:
The proxy settings configuration has same proxy address and value for HTTP
and HTTPS,

- TCP session to proxy sever will not properly be reused. This allows remote
attackers to steal cookie information via crafted HTML document.

- SSl lock consistency with address bar is not ensured. This allows remote
attackers to spoof web sites via a crafted HTML document.

Vulnerability Impact:
Successful exploitation allows attackers to disclose the
sensitive information and view the contents of spoofed site or carry out
phishing attacks.

Affected Software/OS:
Microsoft Internet Explorer versions 8 and 9.

Solution:
No known solution was made available for at least one year since the disclosure
of this vulnerability. Likely none will be provided anymore. General solution options are to upgrade to a newer
release, disable respective features, remove the product or replace the product by another one.

CVSS Score:
4.0

CVSS Vector:
AV:N/AC:H/Au:N/C:P/I:P/A:N

Querverweis: BugTraq ID: 57640
BugTraq ID: 57641
Common Vulnerability Exposure (CVE) ID: CVE-2013-1450
http://pastebin.com/raw.php?i=rz9BcBey
http://www.youtube.com/ChristianHaiderPoC
http://www.youtube.com/watch?v=TPqagWAvo8U
Common Vulnerability Exposure (CVE) ID: CVE-2013-1451
CopyrightCopyright (C) 2013 Greenbone Networks GmbH

Dies ist nur einer von 85075 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2020 E-Soft Inc. Alle Rechte vorbehalten.