[Am-info] IE img/onload can detect presence of files

Fred A. Miller fm@cupserv.org
Fri, 26 Apr 2002 16:11:58 -0400


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

IE img/onload can detect presence of files

A report surfaced indicating that Internet Explorer 6.0 contains a bug
which lets a malicious Web site use the onload() JavaScript function
on the IMG tag to determine if files exist on the client computer.

This vulnerability is not confirmed.

Source: VulnWatch
http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0032.html

- --=20
Fred A. Miller
Systems Administrator
Cornell Univ. Press Services
fm@cupserv.org, www.cupserv.org
- --- SuSE Linux v8.0 Pro---



-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iEYEARECAAYFAjzJtI4ACgkQB9vk4ichYXeHTgCfRS9gysTRPs4F+gP+qBxJebTr
CtIAoK9jgLSjMNND4H3Ihuu4v7OOIGzt
=3D5+cp
-----END PGP SIGNATURE-----