Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

RETIRED: Microsoft Internet Explorer FTP Cross-Site Command Injection Vulnerability

Microsoft Internet Explorer is prone to a vulnerability that occurs because the application fails to adequately sanitize user-supplied data in FTP URI requests.

An attacker can leverage this issue by enticing an unsuspecting user to follow a maliciously crafted URI. Successful exploits will allow attackers to submit arbitrary commands to arbitrary FTP servers on behalf of unsuspecting users.

This issue affects Internet Explorer 5 and 6; prior versions may also be affected.

Note that access to some FTP servers may require valid authentication credentials.

NOTE: This issue is being retired because the issue is already covered in BID 11826 (Microsoft Internet Explorer FTP URI Arbitrary FTP Server Command Execution Vulnerability).







 

Privacy Statement
Copyright 2009, SecurityFocus