CVE
- Id
- 3613
- CVE No.
- CVE-2001-0807
- Status
- Candidate
- Description
- Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client"s hard drive via a SCRIPT tag with a SRC value that points to the text file.
- Phase
- Modified (20020226-01)
- Votes
- ACCEPT(3) Baker, Cole, Prosser | MODIFY(1) Frech | NOOP(3) Armstrong, Bishop, Foat | REVIEWING(2) Christey, Wall
- Comments
- Frech> XF:ie-local-file-disclosure(6688) | Prosser> Legacy product, users should have updated. | Courtesy of Microsoft Security Response Center <secure@microsoft.com>: | | IE 5 is no longer supported - so unless this repro"s on 5.01 or 5.5, we wouldn"t consider doing anything for this. | Christey> ADDREF BID:2836 | URL:http://www.securityfocus.com/bid/2836 | CHANGE> [Christey changed vote from NOOP to REVIEWING]