Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft Internet Explorer File Contents Disclosure Vulnerability

A vulnerability exists in Internet Explorer which could allow a malicious website operator to obtain data from a visiting user's system.

If a known local file on the client filesystem is referenced as script source, some of its contents can be read if they are formatted in a certain way. The contents have to be formatted as though script variables are being assigned values. If a file exists in this manner and resides in a known location, it is possible for a website operator to obtain some or all of it's contents.







 

Privacy Statement
Copyright 2009, SecurityFocus