Information Disclosure Vulnerability in Microsoft Internet Explorer
A vulnerability exists in IE that can lead to information disclosure.
February 21, 2002
ReportedFebruary 21, 2002, by Microsoft.
VERSIONSAFFECTED
Microsoft Internet Explorer (IE) 6.0, 5.5, and 5.01
DESCRIPTION
Avulnerability exists in IE that can lead to information disclosure. This problemstems from the way IE handles VBScript when validating cross-domain access,letting one domain's scripts access another domain's contents within a frame. Anattacker can use scripts to exploit the vulnerability by extracting otherdomains' frame contents to send to the attacker's Web site. The attacker canview files located on the user's local machine or capture the contents ofthird-party Web sites the user visited after leaving the attacker's site. Thevulnerability lets an intruder learn personal information about the user, suchas usernames, passwords, or credit card information.
VENDORRESPONSE
Thevendor, Microsoft, has released SecurityBulletin MS02-009,which addresses this vulnerability, and recommends that affected users apply theappropriate patch listed at Microsoft's Download Center or at the WindowsUpdate Web site.
CREDIT
Discoveredby ZentaiPeter Aron of Ivy Hungary Ltd
Read more about:
MicrosoftAbout the Author
You May Also Like