
|
Title: |
Microsoft Internet Explorer %USERPROFILE% Folder Disclosure Vulnerability |
|
Date: |
5 June 2003 (Last modified: ) |
|
Author: |
Eiji James Yoshida [ptrs-ejy@bp.iij4u.or.jp] |
|
Vulnerable: |
Windows2000 SP3 Internet Explorer 6.0 SP1 |
|
Bugtraq ID: |
|
|
Overview: |
A remote attacker is able to gain access to the path of the %USERPROFILE% folder without guessing a target user name by this vulnerability. ex.) %USERPROFILE% = "C:\Documents and Settings\victim" |
|
Details: |
This vulnerability is in the address of a "Cannot find server"
page. "res://C:\WINNT\System32\shdoclc.dll/dnserror.htm#file://C:\Documents and Settings\%USERNAME%\Desktop\ftp:\\%@\". |
|
Exploit code: |
************************************************** [exploit.html] [ftpexp.html] |
|
Workaround: |
None. |
|
Vendor status: |
Microsoft was notified on 7 November 2002. |
|
Similar vulnerability: |
Microsoft Windows Server 2003 "Shell Folders" Directory Traversal Vulnerability |
Copyright(c) 2003 Eiji James Yoshida. All rights reserved