CVE
- Id
- 4746
- CVE No.
- CVE-2002-0354
- Status
- Candidate
- Description
- The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property.
- Phase
- Proposed (20020502)
- Votes
- ACCEPT(3) Cole, Green, Wall | MODIFY(2) Cox, Frech | NOOP(3) Armstrong, Christey, Foat
- Comments
- CHANGE> [Cox changed vote from ACCEPT to MODIFY] | Cox> Mozilla 0.9.9 is also vulnerable | ADDREF: http://bugzilla.mozilla.org/show_bug.cgi?id=141061 | Christey> REDHAT:RHSA-2002:079 | Christey> BUGTRAQ:20020502 Fix for Mozilla XMLHttpRequest file disclosure vulnerability | URL:http://archives.neohapsis.com/archives/bugtraq/2002-05/0016.html | REDHAT:RHSA-2002:079 | URL:http://www.redhat.com/support/errata/RHSA-2002-079.html | CONECTIVA:CLA-2002:490 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000490 | BID:4628 | URL:http://www.securityfocus.com/bid/4628 | BUGTRAQ:20020504 UPDATE (1-May-2002): Reading local files in Netscape 6 and Mozilla (GM#001-NS) | URL:http://online.securityfocus.com/archive/1/270948 | Christey> XF:mozilla-netscape-xmlhttprequest-redirect(8963) | URL:http://www.iss.net/security_center/static/8963.php | Frech> XF:mozilla-netscape-xmlhttprequest-redirect(8963)