Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/9611 | vendor advisory vdb entry exploit |
http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016881.html | vendor advisory mailing list exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15078 | vdb entry |
http://secunia.com/advisories/10820 | third party advisory vendor advisory |