Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft Internet Explorer dragDrop Method Local File Reading Vulnerability

Internet Explorer could allow a remote user to read files on a vulnerable system using the dragDrop() DHTML method. The local file name must be known by the remote attacker in order to be successful. Reports indicate that relative paths to the file may be used.







 

Privacy Statement
Copyright 2008, SecurityFocus