The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote malicious users to bypass the "File Download - Security Warning" dialog and save arbitrary files with arbitrary extensions via the SaveAs command.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
microsoft ie 6.0 |
||
microsoft internet explorer 6.0 |