Microsoft Internet Explorer prior to 10 allows remote malicious users to obtain sensitive information about the existence of files, and read certain data from files, via a UNC share pathname in the SRC attribute of a SCRIPT element, as demonstrated by reading a name-value pair from a local file via a \\127.0.0.1\C$\ sequence.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
microsoft internet explorer 6 |
||
microsoft internet explorer 9 |
||
microsoft internet explorer 7 |
||
microsoft internet explorer 8 |
||
microsoft internet explorer 7.0.5730 |