BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
RE: IE 6 XML Patch Bypass Oct 08 2003 04:46PM
GreyMagic Software (security greymagic com)
>seems that even with the new Microsoft patch applied, the
>vulnerability works.

There is no reason for it not to work. MS03-040 doesn't claim to offer a
patch for ADODB.Stream or "file:javascript" vulnerabilities. It offers a
patch to the variation of the application/hta content-type header in obj...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus