|
|
Opera JavaScript Java方法访问漏洞 发布时间:2003-04-03 更新时间:2003-04-03 严重程度:中 威胁程度:普通用户访问权限 错误类型:设计错误 利用方式:客户机模式
BUGTRAQ ID:7271
受影响系统Opera Software Opera Web Browser 6.0.1 win32
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Advanced Server SP1
- Microsoft Windows 2000 Advanced Server SP2
- Microsoft Windows 2000 Datacenter Server
- Microsoft Windows 2000 Datacenter Server SP1
- Microsoft Windows 2000 Datacenter Server SP2
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Server SP1
- Microsoft Windows 2000 Server SP2
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows 98SE
- Microsoft Windows ME
- Microsoft Windows NT Enterprise Server 4.0
- Microsoft Windows NT Enterprise Server 4.0 SP1
- Microsoft Windows NT Enterprise Server 4.0 SP2
- Microsoft Windows NT Enterprise Server 4.0 SP3
- Microsoft Windows NT Enterprise Server 4.0 SP4
- Microsoft Windows NT Enterprise Server 4.0 SP5
- Microsoft Windows NT Enterprise Server 4.0 SP6
- Microsoft Windows NT Enterprise Server 4.0 SP6a
- Microsoft Windows NT Server 4.0
- Microsoft Windows NT Server 4.0 SP1
- Microsoft Windows NT Server 4.0 SP2
- Microsoft Windows NT Server 4.0 SP3
- Microsoft Windows NT Server 4.0 SP4
- Microsoft Windows NT Server 4.0 SP5
- Microsoft Windows NT Server 4.0 SP6
- Microsoft Windows NT Server 4.0 SP6a
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows XP Home
- Microsoft Windows XP Professional 详细描述 Opera在通过Javascript中调用JAVA方法时存在问题,可导致用户浏览恶意网页时被执行任意命令。
如果在Javascript中嵌入一些恶意JAVA方法,如exec等,可导致任意命令被执行,也可以使用一些其他JAVA方法,获得用户IP地址等等。如下可以获得本地IP地址:
var host=java.net.InetAddress.getLocalHost();
测试代码 演示页面如下:
http://usuarios.lycos.es/idoru/petaopera.html
http://usuarios.lycos.es/idoru/sockets.html
解决方案 升级到Opera 7.0.2版本:
http://www.opera.com
相关信息 "David F. Madrid" <conde0@telefonica.net>.
参考:http://www.securityfocus.com/archive/1/317360
相关主页:http://www.opera.com/
|