Microsoft Internet Explorer Dynamic...

- AV AC AU C I A
发布: 2005-01-13
修订: 2025-04-13

Microsoft Internet Explorer is reported prone to a file download security warning bypass weakness. This issue may be exploited to download a malicious file to the client system. It is reported that this security warning can be bypassed by creating a document containing a specially crafted HTML BODY tag and a dynamic IFRAME. By enticing a user to visit a site, the attacker can potentially plant malicious files on vulnerable systems in order to execute malicious code. It should be noted that although no security warning appears, the standard download confirmation widnow still appears and requires the user to confirm the download prior to any files being placed on the unsuspecting user's computer. This vulnerability may be combined with other issues in the browser or the affected computer to aid in various attacks. It should also be noted that Symantec has been unable to replicate this issue. Furthermore Microsoft has stated that this is not a vulnerability. This BID will be updated...

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息