RE: Microsoft Internet Explorer 'Folder View for FTP sites' Scrip t Execution vulnerability

From: Thor Larholm (Thorat_private)
Date: Thu Jun 06 2002 - 14:55:53 PDT

  • Next message: SGI Security Coordinator: "MediaMail vulnerability"

    I was a bit confused as to whether this had to be triggered _from_ the My
    Computer zone, but tests quickly proofed that this is definitely remotely
    exploitable.
    
    To clear things up, this is yet another XSS vulnerability that allows
    arbitrary HTML to be inserted in the My Computer zone. This makes it quite
    easy to e.g. execute arbitrary commands, undoubtedly a more fun
    demonstration:
    
    http://jscript.dk/Jumper/xploit/ftpfolderview.html
    
    Status: 18 unpatched vulnerabilities.
    
    http://jscript.dk/Unpatched/
    
    
    Regards
    Thor Larholm
    Jubii A/S - Internet Programmer
    



    This archive was generated by hypermail 2b30 : Thu Jun 06 2002 - 15:44:04 PDT