Microsoft Internet Explorer Header Handling 'res://' Information Disclosure Vulnerability
BID:28667
Info
Microsoft Internet Explorer Header Handling 'res://' Information Disclosure Vulnerability
| Bugtraq ID: | 28667 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 07 2008 12:00AM |
| Updated: | Apr 08 2008 03:58AM |
| Credit: | 0x000000 # The Hacker Webzine |
| Vulnerable: |
Microsoft Internet Explorer 7.0.5730 .11 Microsoft Internet Explorer 7.0 beta3 Microsoft Internet Explorer 7.0 beta2 Microsoft Internet Explorer 7.0 beta1 Microsoft Internet Explorer 7.0 |
| Not Vulnerable: |
Microsoft Internet Explorer 8 Beta 1 |
Discussion
Microsoft Internet Explorer Header Handling 'res://' Information Disclosure Vulnerability
Microsoft Internet Explorer is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to obtain potentially sensitive information from the local computer. Information obtained may aid in further attacks.
This issue affects Internet Explorer 7. Reportedly, Internet Explorer 8 is not vulnerable, but this has not been confirmed.
This issue may be related to the vulnerability discussed in BID 28581 (Microsoft Internet Explorer 'ieframe.dll' Script Injection Vulnerability).
Microsoft Internet Explorer is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to obtain potentially sensitive information from the local computer. Information obtained may aid in further attacks.
This issue affects Internet Explorer 7. Reportedly, Internet Explorer 8 is not vulnerable, but this has not been confirmed.
This issue may be related to the vulnerability discussed in BID 28581 (Microsoft Internet Explorer 'ieframe.dll' Script Injection Vulnerability).
Exploit / POC
Microsoft Internet Explorer Header Handling 'res://' Information Disclosure Vulnerability
Attackers can leverage this issue by enticing an unsuspecting user to view a malicious web document.
The following example exploit code is available:
Attackers can leverage this issue by enticing an unsuspecting user to view a malicious web document.
The following example exploit code is available:
Solution / Fix
Microsoft Internet Explorer Header Handling 'res://' Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Internet Explorer Header Handling 'res://' Information Disclosure Vulnerability
References:
References:
- Internet Explorer 7 Header Forwards (The Hacker Webzine)
- Internet Explorer Homepage (Microsoft)