[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

IE File Download Dialog Vulnerability

ID: oval:org.mitre.oval:def:948Date: (C)2004-04-29   (M)2021-07-27
Class: VULNERABILITYFamily: windows




Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file download dialogs, which eventually cause Internet Explorer to execute the program, as demonstrated using a large number of FRAME or IFRAME tags, aka the "File Download Dialog Vulnerability."

Platform:
Microsoft Windows 98
Microsoft Windows ME
Microsoft Windows NT
Microsoft Windows 2000
Product:
Microsoft Internet Explorer
Reference:
CVE-2003-0309
CVE    1
CVE-2003-0309

© SecPod Technologies