Microsoft Internet Explorer XMLHTTP...

- AV AC AU C I A
发布: 2001-12-15
修订: 2025-04-13

An issue exists in handling of HTTP redirects in the Microsoft XMLHTTP ActiveX component. When a server responds to a XMLHTTP request with a redirect, the XMLHTTP method will access the content at the location of the redirect without considering the URL protocol. If the redirect is to a file on the user's filesystem, the contents of the file will become available to the script code that invoked the ActiveX object. This could lead to a disclosure of sensitive information to remote attackers.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息