Microsoft Internet Explorer Combined JavaScript and XML Remote Information Disclosure Vulnerability
BID:28143
Info
Microsoft Internet Explorer Combined JavaScript and XML Remote Information Disclosure Vulnerability
| Bugtraq ID: | 28143 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2008 12:00AM |
| Updated: | Mar 07 2008 07:31PM |
| Credit: | Ronald van den Heetkamp discovered this issue. |
| Vulnerable: |
Microsoft Internet Explorer 7.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer Combined JavaScript and XML Remote Information Disclosure Vulnerability
Microsoft Internet Explorer is prone to a remote information-disclosure vulnerability because of a flaw in the interaction between JavaScript and XML processing in Internet Explorer.
To exploit this issue, an attacker must entice an unsuspecting user to visit a malicious website.
Successfully exploiting this issue allows remote attackers to gain access to the first line of arbitrary files located on computers running the vulnerable application.
Microsoft Internet Explorer is prone to a remote information-disclosure vulnerability because of a flaw in the interaction between JavaScript and XML processing in Internet Explorer.
To exploit this issue, an attacker must entice an unsuspecting user to visit a malicious website.
Successfully exploiting this issue allows remote attackers to gain access to the first line of arbitrary files located on computers running the vulnerable application.
Exploit / POC
Microsoft Internet Explorer Combined JavaScript and XML Remote Information Disclosure Vulnerability
Attackers can leverage this issue by enticing an unsuspecting user to open a malicious web document.
The following exploit code is available:
Attackers can leverage this issue by enticing an unsuspecting user to open a malicious web document.
The following exploit code is available:
Solution / Fix
Microsoft Internet Explorer Combined JavaScript and XML Remote Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Internet Explorer Combined JavaScript and XML Remote Information Disclosure Vulnerability
References:
References:
- Internet Explorer Homepage (Microsoft)
- MSIE7 Remote File Read Access. (Ronald van den Heetkamp)