The latest sogou expressway browser version 5.0 and earlier has a cross-origin vulnerability.
The latest sogou expressway browser version 5.0 and earlier has a cross-origin vulnerability.
Download sogou high-speed browser 5.0
http://ie.sogou.com/
Sogou high-speed browsers have always been IE-based browsers.
When the problem occurs in CSS Parse, the content after fontFamily is treated as value, so that cross-domain---can be implemented --.
Construct two cross-region POC tests:
Test1.html
Test2.html
Search for dog high-speed browser 5.020.test2.html
However, you must change to the IE compatibility mode.
This is a vulnerability in the IE kernel browser...
Successful cross-domain reading of content in test1.html...
I will not send a picture for versions earlier than 5.0, because it does exist. This is a feature of sogou's high-speed browser mode. Each version has the IE compatibility mode...
In test2.html, test.html is loaded as a CSS file through @ import, rendering the file into the current DOM, and accessing this content through document. body. currentStyle. fontFamily. The problem occurs on the page content of CSS transform.
Solution:
Patch