Microsoft Internet Explorer XML External Entity Information Disclosure Vulnerability
BID:108018
Info
Microsoft Internet Explorer XML External Entity Information Disclosure Vulnerability
| Bugtraq ID: | 108018 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 12 2019 12:00AM |
| Updated: | Apr 12 2019 12:00AM |
| Credit: | John Page (hyp3rlinx). |
| Vulnerable: |
Microsoft Windows Server 2012 R2 0 Microsoft Windows 7 Microsoft Windows 10 Microsoft Internet Explorer 11 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer XML External Entity Information Disclosure Vulnerability
Microsoft Internet Explorer is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information. Successful exploits may lead to other attacks.
Microsoft Internet Explorer is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information. Successful exploits may lead to other attacks.
Exploit / POC
Microsoft Internet Explorer XML External Entity Information Disclosure Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
Microsoft Internet Explorer XML External Entity Information Disclosure Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Microsoft Internet Explorer XML External Entity Information Disclosure Vulnerability
References:
References: