CVE-2010-0255
기본정보
  • 공개일 : 2010-02-05
  • 변경일 : 2010-08-21
CVSS 평가
  • 위험도: 4.3
  • 액세스 벡터 : NETWORK
  • 액세스 복잡성 : 보통
  • 인증 : 없음
  • 기밀성 영향 : 부분
  • 무결성 영향 : 없음
  • 가용성 영향 : 없음
  • 출처 : http://nvd.nist.gov
  • 공개일 : 2010-02-06
설명

Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving JavaScript exploit code that constructs a reference to a file://127.0.0.1 URL, aka the dynamic OBJECT tag vulnerability, as demonstrated by obtaining the data from an index.dat file, a variant of CVE-2009-1140 and related to CVE-2008-1448.

참조
취약 소프트웨어
  • microsoft ie 7
  • microsoft ie 6
  • microsoft ie 6
  • microsoft ie 5.01
  • microsoft ie 8