Microsoft IE and OE XML Stylesheets Active Scripting Vulnerability
BID:2633
Info
Microsoft IE and OE XML Stylesheets Active Scripting Vulnerability
| Bugtraq ID: | 2633 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1325 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 20 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | Discovered and posted to Bugtraq on April 20, 2001 by Georgi Guninski <[email protected]>. |
| Vulnerable: |
Microsoft Outlook Express 5.5 Microsoft Internet Explorer 5.5 Microsoft Internet Explorer 5.0 |
| Not Vulnerable: | |
Discussion
Microsoft IE and OE XML Stylesheets Active Scripting Vulnerability
A vulnerability exists in the handling of XML stylesheets in Internet Explorer and Outlook Express. If active scripting is disabled in all security zones, IE and OE will still allow script to run if it is contained in the stylesheet of an XML page.
A vulnerability exists in the handling of XML stylesheets in Internet Explorer and Outlook Express. If active scripting is disabled in all security zones, IE and OE will still allow script to run if it is contained in the stylesheet of an XML page.
Exploit / POC
Microsoft IE and OE XML Stylesheets Active Scripting Vulnerability
Georgi Guninski <[email protected]> has provided the following example:
http://www.guninski.com/xstyle.eml
Georgi Guninski <[email protected]> has provided the following example:
http://www.guninski.com/xstyle.eml
Solution / Fix
Microsoft IE and OE XML Stylesheets Active Scripting Vulnerability
Solution:
Microsoft has addressed this issue in a patch originally for a Windows Script Host issue. However this patch will remedy the current Internet Explorer and Outlook Express issue. The patch is a collection of all IIS4 and IIS5 hotfixes since SP5 and W2K Gold. All future IIS patches will be released in the same manner.
Microsoft Outlook Express 5.5
Microsoft Internet Explorer 5.0
Microsoft Internet Explorer 5.5
Solution:
Microsoft has addressed this issue in a patch originally for a Windows Script Host issue. However this patch will remedy the current Internet Explorer and Outlook Express issue. The patch is a collection of all IIS4 and IIS5 hotfixes since SP5 and W2K Gold. All future IIS patches will be released in the same manner.
Microsoft Outlook Express 5.5
-
Microsoft scr55en
Windows 95, 98, NT 4.0
http://www.microsoft.com/scripting/downloads/v55/other/scr55en.exe -
Microsoft scripten
Windows 2000
http://www.microsoft.com/scripting/downloads/v51/windows2000/scripten. exe -
Microsoft ste51en
Windows 95, 98, NT 4.0
http://www.microsoft.com/scripting/downloads/v51/other/ste51en.exe
Microsoft Internet Explorer 5.0
-
Microsoft scr55en
Windows 95, 98, NT 4.0
http://www.microsoft.com/scripting/downloads/v55/other/scr55en.exe -
Microsoft scripten
Windows 2000
http://www.microsoft.com/scripting/downloads/v51/windows2000/scripten. exe -
Microsoft ste51en
Windows 95, 98, NT 4.0
http://www.microsoft.com/scripting/downloads/v51/other/ste51en.exe
Microsoft Internet Explorer 5.5
-
Microsoft scr55en
Windows 95, 98, NT 4.0
http://www.microsoft.com/scripting/downloads/v55/other/scr55en.exe -
Microsoft scripten
Windows 2000
http://www.microsoft.com/scripting/downloads/v51/windows2000/scripten. exe -
Microsoft ste51en
Windows 95, 98, NT 4.0
http://www.microsoft.com/scripting/downloads/v51/other/ste51en.exe
References
Microsoft IE and OE XML Stylesheets Active Scripting Vulnerability
References:
References:
- Microsoft Security Bulletin (MS01-015) (Microsoft)