Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2007-3576

EPSS 27.56% · P96
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2007-3576

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Microsoft Internet Explorer 6 executes web script from URIs of arbitrary scheme names ending with the "script" character sequence, using the (1) vbscript: handler for scheme names with 7 through 9 characters, and the (2) javascript: handler for scheme names with 10 or more characters, which might allow remote attackers to bypass certain XSS protection schemes. NOTE: other researchers dispute the significance of this issue, stating "this only works when typed in the address bar.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft Internet Explorer安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Internet Explorer(IE)是美国微软(Microsoft)公司的一款Windows操作系统附带的Web浏览器。 Microsoft Internet Explorer 6 执行任意计划名并以"script"字符序列结尾的URIs中的web脚本,运行(1) vbscript:具有7至9字符的计划名的处理器,以及(2) javascript:具有10或更多字符的计划名的处理器, 这会允许远程攻击者绕过某些XSS保护计划。 注意:其他研究人员质疑此问题的严重性。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2007-3576

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2007-3576

Please Login to view more intelligence information

Same Patch Batch · n/a · 2007-07-05 · 33 CVEs total

CVE-2007-3581Jedox Palo 远程欺骗网络漏洞
CVE-2007-3571Apache web 远程攻击漏洞
CVE-2007-3570Linux Access Gateway 远程攻击漏洞
CVE-2007-3569Oliver 多个跨站脚本攻击漏洞
CVE-2007-3568ImLib库_LoadBMP函数拒绝服务漏洞
CVE-2007-3567MySQLDumper绕过Apache访问控制认证漏洞
CVE-2007-3012Fujitsu PRIMERGY BX300刀片服务器信息泄露漏洞
CVE-2007-3011Fujitsu ServerView DBASCIIAccess脚本远程代码执行漏洞
CVE-1999-1591Microsoft VisualInterDev 6.0 - IIS4无认证管理漏洞
CVE-2007-3588VBZooM SQL注入漏洞
CVE-2007-3587MyCMS 多个输入验证漏洞
CVE-2007-3586MyCMS 多个输入验证漏洞
CVE-2007-3585MyCMS 多个输入验证漏洞
CVE-2007-3584Postnuke PNphpBB2 SQL注入漏洞
CVE-2007-3583Girlserv Ads Details_News.PHP SQL注入漏洞
CVE-2007-3582SuperCali Index.PHP SQL注入漏洞
CVE-2007-3589B1GBB id参数多个SQL注入漏洞
CVE-2007-3580PHPIDS 远程注入漏洞
CVE-2007-3579PHPIDS 远程注入漏洞
CVE-2007-3578PHPIDS 远程注入漏洞

Showing top 20 of 33 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2007-3576

No comments yet


Leave a comment