CVE-2007-4356

Microsoft Internet Explorer 6 and 7 embeds FTP credentials in HTML files that are retrieved during an FTP session, which allows context-dependent attackers to obtain sensitive information by reading the HTML source, as demonstrated by a (1) .htm, (2) .html, or (3) .mht file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:*

History

21 Nov 2024, 00:35

Type Values Removed Values Added
References () http://blog.washingtonpost.com/securityfix/2007/08/ftp_files_expose_web_site_cred.html - () http://blog.washingtonpost.com/securityfix/2007/08/ftp_files_expose_web_site_cred.html -
References () http://osvdb.org/36400 - () http://osvdb.org/36400 -
References () http://secunia.com/advisories/26427 - Vendor Advisory () http://secunia.com/advisories/26427 - Vendor Advisory

Information

Published : 2007-08-15 00:17

Updated : 2024-11-21 00:35


NVD link : CVE-2007-4356

Mitre link : CVE-2007-4356

CVE.ORG link : CVE-2007-4356


JSON object : View

Products Affected

microsoft

  • internet_explorer