
|
Title: |
Microsoft Internet Explorer 'Folder View for FTP sites' Script Execution Vulnerability |
|
Date: |
7 June 2002 (Last modified: ) |
|
Author: |
Eiji James Yoshida [zaddik@geocities.co.jp] |
|
Risk: |
Medium |
|
Vulnerable: |
Windows2000 SP2 IE5.5SP1 |
|
Bugtraq ID: |
|
|
Patch: |
Windows2000 SP3 (Q316890) |
|
Overview: |
IE allows running Malicious Scripts due to a bug in 'folder View for FTP sites'. If you enable both an 'Enable folder view for FTP sites' IE Advanced
Setting * It's important that the script runs in the My Computer Zone!
|
|
Details: |
The problem is in FTP.HTT invoked by the 'folder view for FTP
sites' feature. --------------------FTP.HTT-------------------- This '%THISDIRPATH%' is not escaped. (Example 1) (Example 2)
|
|
Exploit code: |
<a href="ftp://%22%3e%3cscript%3ealert(%22Exploit%22)%3b%3c%2fscript%3e%20" target="_blank">Exploit</a> |
|
Demonstration: |
|
|
Workaround: |
Disable either 'Enable folder view for FTP sites' IE Advanced
Setting |
|
Vendor status: |
Microsoft was notified on 21 December 2001. |
|
Similar vulnerabilities: |
|
Copyright(c) 2002 Eiji James Yoshida. All rights reserved