Microsoft Internet Explorer XMLHTTP File Disclosure Vulnerability
BID:3699
Info
Microsoft Internet Explorer XMLHTTP File Disclosure Vulnerability
| Bugtraq ID: | 3699 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2001 12:00AM |
| Updated: | Dec 15 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by jelmer <[email protected]>. |
| Vulnerable: |
Microsoft XML Core Services 5.0 SP1 Microsoft XML Core Services 3.0 Microsoft XML Core Services 2.6 Microsoft Windows XP Professional Microsoft Windows XP Home Microsoft SQL Server 2000 SP2 Microsoft SQL Server 2000 SP1 Microsoft SQL Server 2000 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer XMLHTTP File Disclosure Vulnerability
An issue exists in handling of HTTP redirects in the Microsoft XMLHTTP ActiveX component.
When a server responds to a XMLHTTP request with a redirect, the XMLHTTP method will access the content at the location of the redirect without considering the URL protocol. If the redirect is to a file on the user's filesystem, the contents of the file will become available to the script code that invoked the ActiveX object.
This could lead to a disclosure of sensitive information to remote attackers.
An issue exists in handling of HTTP redirects in the Microsoft XMLHTTP ActiveX component.
When a server responds to a XMLHTTP request with a redirect, the XMLHTTP method will access the content at the location of the redirect without considering the URL protocol. If the redirect is to a file on the user's filesystem, the contents of the file will become available to the script code that invoked the ActiveX object.
This could lead to a disclosure of sensitive information to remote attackers.
Exploit / POC
Microsoft Internet Explorer XMLHTTP File Disclosure Vulnerability
jelmer <[email protected]> has provided the following working example:
http://www.xs4all.nl/~jkuperus/bug.htm
jelmer <[email protected]> has provided the following working example:
http://www.xs4all.nl/~jkuperus/bug.htm
Solution / Fix
Microsoft Internet Explorer XMLHTTP File Disclosure Vulnerability
Solution:
There have been reports that the cumulative patch (Q323759) described in Microsoft Security Bulletin MS02-047 may cause the vendor-supplied fix for this vulnerability to stop functioning on Windows XP systems running Microsoft Internet Explorer 6. This has the potential to re-expose patched systems to this issue.
Fixes are available in the attached reference (Microsoft Security Bulletin MS02-008).
Solution:
There have been reports that the cumulative patch (Q323759) described in Microsoft Security Bulletin MS02-047 may cause the vendor-supplied fix for this vulnerability to stop functioning on Windows XP systems running Microsoft Internet Explorer 6. This has the potential to re-expose patched systems to this issue.
Fixes are available in the attached reference (Microsoft Security Bulletin MS02-008).
References
Microsoft Internet Explorer XMLHTTP File Disclosure Vulnerability
References:
References:
- Microsoft Security Bulletin MS02-008 (Microsoft)
- Microsoft Security Bulletin MS02-047 (Microsoft)
- Microsoft Windows Update (Microsoft)