The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin MS02-009: Incorrect VBScript Handling in IE can Allow Web Pages to Read Local Files
Time: 00:25 EST/05:25 GMT | News Source: ActiveWin.com | Posted By: Matthew Sabean

Frames are used in Internet Explorer to provide for a fuller browsing experience. By design, scripts in the frame of one site or domain should be prohibited from accessing the content of frames in another site or domain. However, a flaw exists in how VBScript is handled in IE relating to validating cross-domain access. This flaw can allow scripts of one domain to access the contents of another domain in a frame.

A malicious user could exploit this vulnerability by using scripting to extract the contents of frames in other domains, then sending that content back to their web site. This would enable the attacker to view files on the user's local machine or capture the contents of third-party web sites the user visited after leaving the attacker’s site. The latter scenario could, in the worst case, enable the attacker to learn personal information like user names, passwords, or credit card information. In both cases, the user would either have to go to a site under the attacker's control or view an HTML email sent by the attacker. In addition, the attacker would have to know the exact name and location of any files on the user's system. Further, the attacker could only gain access to files that can be displayed in a browser window, such as text files, HTML files, or image files.

A complete list of all Security Bulletins can be found in our Microsoft Security Bulletin Summary List in our Support Section.

Write Comment
Return to News

  Displaying 426 through 428 of 428
Prev | First
  The time now is 3:34:32 PM ET.
Any comment problems? E-mail us
#426 By 4240821 (193.228.48.158) at 2/12/2025 11:50:57 PM
https://hotpic.cc/album/mzWukDHcrCgbC
https://hotpic.cc/album/CMAdZHPBYgU0r
https://hotpic.cc/album/WEmuMwwjeTpZS
https://hotpic.cc/album/mpYOtrgYM8GdT
https://hotpic.cc/album/hkupjJLGIyTzu
https://hotpic.cc/album/6Kv0OMAAcKzOp
https://hotpic.cc/album/5DrqbiTzc3Xoc
https://hotpic.cc/album/f9vgmrKPpqo7V
https://hotpic.cc/album/U8AgFzsGSMdSC
https://hotpic.cc/album/CR2tHfKH3HKA3

#427 By 4240821 (166.1.149.27) at 2/13/2025 11:10:16 AM
https://hotpic.cc/album/lEa2nOHfd3rSF
https://hotpic.cc/album/w3oI019it5zVY
https://hotpic.cc/album/6Kv0OMAAcKzOp
https://hotpic.cc/album/u4KxW7kboQpl8
https://hotpic.cc/album/JZNDXPgMblix6
https://hotpic.cc/album/wTqKdTLiTh4I3
https://hotpic.cc/album/sEXzhF6nOeQPr
https://hotpic.cc/album/qPpa5kbi1JEdP
https://hotpic.cc/album/QiY2kPiLIym7H
https://hotpic.cc/album/mt5nsueWdkKTZ

#428 By 4240821 (142.111.253.203) at 2/14/2025 2:13:33 PM
https://hotpic.cc/album/IXSdP2krZTTy0
https://hotpic.cc/album/KsVPzCcBJIJ3C
https://hotpic.cc/album/8PdjaKdjd6RRf
https://hotpic.cc/album/RNxmJ8CLdBzYl
https://hotpic.cc/album/w3oI019it5zVY
https://hotpic.cc/album/lhPgKNnSi8ZbV
https://hotpic.cc/album/ImzcGijwQR45j
https://hotpic.cc/album/MXo1lzgOUV3QC
https://hotpic.cc/album/DGLn1swh8Uz08
https://hotpic.cc/album/0GbgTb9v7Gb7u

Write Comment
Return to News
  Displaying 426 through 428 of 428
Prev | First
  The time now is 3:34:32 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *