Описание
Microsoft XML Core Services (aka MSXML) 3.0 and 6.0 does not properly restrict the information transmitted by Internet Explorer during a download action, which allows remote attackers to discover (1) full pathnames on the client system and (2) local usernames embedded in these pathnames via a crafted web site, aka "MSXML Entity URI Vulnerability."
Ссылки
- Vendor Advisory
- Permissions Required
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Permissions Required
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Одно из
EPSS
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
Microsoft XML Core Services (aka MSXML) 3.0 and 6.0 does not properly restrict the information transmitted by Internet Explorer during a download action, which allows remote attackers to discover (1) full pathnames on the client system and (2) local usernames embedded in these pathnames via a crafted web site, aka "MSXML Entity URI Vulnerability."
Уязвимость программного обеспечения Microsoft XML Core Services, позволяющая удаленному злоумышленнику нарушить конфиденциальность защищаемой информации
EPSS
4.3 Medium
CVSS2