The Xmlhttprequest Object (xmlhttp) In Netscape vulnerability report
vulnerabilities.aspcode.net
Phase:
The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property.
References
BUGTRAQ:Tuesday, April 30, 2002 Reading local files in Netscape 6 and Mozilla (GM#001-NS) | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=102017952204097&w=2 | NTBUGTRAQ:Tuesday, April 30, 2002 Reading local files in Netscape 6 and Mozilla (GM#001-NS) | URL:http://marc.the
Votes:
Proposed (Thursday, May 02, 2002)
Comments:
ACCEPT(3) Wall, Cole, Green | MODIFY(2) Frech, Cox | NOOP(3) Foat, Armstrong, Christey
F7:
CHANGE> [Cox changed vote from ACCEPT to MODIFY] | Cox> Mozilla 0.9.9 is also vulnerable | ADDREF: http://bugzilla.mozilla.org/show_bug.cgi?id=141061 | Christey> REDHAT:RHSA-2002:079 | Christey> BUGTRAQ:20020502 Fix for Mozilla XMLHttpRequest file disclosure vulnerability | URL:http://archives.neohapsis.com/archives/bugtraq/2002-05/0016.html | REDHAT:RHSA-2002:079 | URL:http://www.redhat.com/support/errata/RHSA-2002-079.html | CONECTIVA:CLA-2002:490 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000490 | BID:4628 | URL:http://www.securityfocus.com/bid/4628 | BUGTRAQ:20020504 UPDATE (1-May-2002): Reading local files in Netscape 6 and Mozilla (GM#001-NS) | URL:http://online.securityfocus.com/archive/1/270948 | Christey> XF:mozilla-netscape-xmlhttprequest-redirect(8963) | URL:http://www.iss.net/security_center/static/8963.php | Frech> XF:mozilla-netscape-xmlhttprequest-redirect(8963)
Tagged as
XMLHttpRequest
object