Microsoft IE5 Download Behavior...

- AV AC AU C I A
发布: 1999-09-27
修订: 2025-04-13

The "download behavior" feature of Microsoft's Internet Explorer 5 may allow a malicious web site operator to read files on an IE5 client computer or on a computer that is in the client's 'Local Intranet' web content zone. IE5 introduced a new feature called DHTML Behaviors. DHTML Behaviors allow web developers to encapsulate methods, properties and events that can then be applied to HTML and XML elements. IE5 comes with set of built-in DHTML behaviors. One of them is the "#default#download" behaviors. This behavior defines a new Javascript method called "startDownload" that takes two parameters, the file to download and a function to call once the file has been downloaded. By default the "startDownload" method checks that the file to be downloaded is in the same web content zone as the file calling the method. When both the file to be downloaded and the file executing the behavior are in the same security zone, the client will safely download the requested file and subsequently...

当前有1条漏洞利用/PoC
当前有0条受影响产品信息