漏洞描述 Microsoft Internet Explorer 8存在非可信搜索路径漏洞。此漏洞允许本地用户通过对当前工作目录植入特洛伊木马IEShims.dll来获取权限,如包含HTML文件的Desktop目录。
相关漏洞推荐 POC CVE-2018-2392: SAP Internet Graphics Server (IGS) - XML External Entity Injection POC CVE-2021-36646: KodExplorer - Cross-Site Scripting POC CVE-2021-41569: SAS/Internet 9.4 1520 - Local File Inclusion POC CVE-2021-46387: Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting POC CVE-2023-49489: KodeExplorer 4.51 - Reflective Cross Site Scripting (XSS) POC CNVD-2021-14536: Ruijie RG-UAC Unified Internet Behavior Management Audit System - Information Disclosure POC aem-explorer-nodetypes: Adobe AEM Explorer NodeTypes Exposure POC aws-s3-explorer: Amazon Web Services S3 Explorer - Detect POC hanta-rce: Hanta Internet Behavior Management System - Remote Code Execution Microsoft Internet Explorer CVE-2014-6347内存损坏漏洞 Microsoft Internet Explorer CVE-2016-3298信息泄露漏洞 Microsoft Internet Explorer CVE-2016-3385内存损坏漏洞 Microsoft Internet Explorer CVE-2014-8966远程内存损坏漏洞