Information Disclosure Vulnerability in Microsoft XML Core Services

 
Feb 19, 2002

A vulnerability exists in how the XMLHTTP control applies Microsoft Internet Explorer (IE) security-zone settings to a redirected data stream that XMLHTTP returns as a response to a request for data from a website. An attacker can exploit this problem and specify a datasource on the user's local system.

Microsoft has provided a bulletin and a patch.

Information Disclosure Vulnerability in Microsoft XML Core Services

Add a Comment
(If you subscribe, any new posts to this thread will be sent to your email address.)
  
Privacy | FAQ | Site Map | About | Guidelines | Contact | Advertising | What is ColdFusion?
House of Fusion | ColdFusion Jobs | Blog of Fusion | AHP Hosting