IE8无疑是微软迄今为止最佳的浏览器,但IE8还是存在一些问题。
127.0.0.1 google.08.cn
127.0.0.1 111.366blog.info
127.0.0.1 xiaoxiaojd.3322.org
127.0.0.1 5t.366blog.info
127.0.0.1 77776666.7766.org
127.0.0.1 3e.366blog.info
127.0.0.1 44ads.ppsussiowa.info
127.0.0.1 yyyy.366blog.info
127.0.0.1 20100309.xcvbvbgn.3322.org
127.0.0.1 www.taobao-taobaowang.com
127.0.0.1 zc3303490.a26.czwow.com
127.0.0.1 afc.bij.pl
127.0.0.1 aez.bij.pl
127.0.0.1 bb.366online.info
127.0.0.1 ui.buo.cc
127.0.0.1 a.brsqb.cn
127.0.0.1 ferrari12.8800.org
127.0.0.1 www.hngqt.cn
127.0.0.1 job.icxo.com
127.0.0.1 111.366blog.info
127.0.0.1 xiaoxiaojd.3322.org
127.0.0.1 5t.366blog.info
127.0.0.1 77776666.7766.org
127.0.0.1 3e.366blog.info
127.0.0.1 44ads.ppsussiowa.info
127.0.0.1 yyyy.366blog.info
127.0.0.1 20100309.xcvbvbgn.3322.org
127.0.0.1 www.taobao-taobaowang.com
127.0.0.1 zc3303490.a26.czwow.com
127.0.0.1 afc.bij.pl
127.0.0.1 aez.bij.pl
127.0.0.1 bb.366online.info
127.0.0.1 ui.buo.cc
127.0.0.1 a.brsqb.cn
127.0.0.1 ferrari12.8800.org
127.0.0.1 www.hngqt.cn
127.0.0.1 job.icxo.com
世界经理人被嵌入恶意代码,在用户不知情的情况下,可以导致电脑被黑客控制并且被窃取敏感信息。
[!]包含版本 :v6.5
[!]漏洞文件 :user/UpFileSave.asp
[!]漏洞描述 :通过自己构造参数AutoReName=3,可以将上传的文件名保存原样,通过截断可以直接得到SHELL 限制,后台禁止了注册,或者禁止了上传,或者把user目录删除了,优点是不用找后台,开放就死
[!]危害程度 :高
[!]漏洞文件 :user/UpFileSave.asp
[!]漏洞描述 :通过自己构造参数AutoReName=3,可以将上传的文件名保存原样,通过截断可以直接得到SHELL 限制,后台禁止了注册,或者禁止了上传,或者把user目录删除了,优点是不用找后台,开放就死
[!]危害程度 :高
在最新的discuz! 7.2中自带了一个新的应用程序插件manyou。恰恰在这个新插件中,没有对传入的参数进行检查,在GPC为off的情况下,导致注入漏洞的产生。
# ie_iepeers_pointer.rb
#
# Microsoft Internet Explorer iepeers.dll use-after-free exploit for the Metasploit Framework
#
# Tested successfully on the following platforms:
# - Microsoft Internet Explorer 7, Windows Vista SP2
# - Microsoft Internet Explorer 7, Windows XP SP3
# - Microsoft Internet Explorer 6, Windows XP SP3
#
# Exploit found in-the-wild. For additional details:
# http://www.rec-sec.com/2010/03/10/internet-explorer-iepeers-use-after-free-exploit/ #
# Trancer
# http://www.rec-sec.com
##
#
# Microsoft Internet Explorer iepeers.dll use-after-free exploit for the Metasploit Framework
#
# Tested successfully on the following platforms:
# - Microsoft Internet Explorer 7, Windows Vista SP2
# - Microsoft Internet Explorer 7, Windows XP SP3
# - Microsoft Internet Explorer 6, Windows XP SP3
#
# Exploit found in-the-wild. For additional details:
# http://www.rec-sec.com/2010/03/10/internet-explorer-iepeers-use-after-free-exploit/ #
# Trancer
# http://www.rec-sec.com
##









