The Microsoft Java implementation, as used in Internet Explorer, allows remote malicious users to read arbitrary local files and network shares via an applet tag with a codebase set to a "file://%00" (null character) URL.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
microsoft java virtual machine 1.1 |