IE drag and drop vulnerability detailed

xiaoxiao2021-03-06  66

The use of the vulnerability is mainly combined with the three vulnerabilities of IE. The first is that when the transparent filter of the IMG element can be in response to the event, the code is as follows: (not original, add notes easy to understand) - -------------------------------------------------- -------- CODE-1 --------------------------------------- ------------------------- ! - Vulnerability Description: When the user is in a picture (IMG element, a scroll bar we constructed) When dragging and drop, we can make a special layer in the cursor that is being dragged and dropped by setting some drag and drop events (ONDRAGSTART & LANDRAGOVER). When we release the mouse, this IMG element's DYNSRC property is defined. The file will prevent this layer, and this layer is pointed to by the user's local directory (start directory) ->