Madrid, March 1, 2006 - The company CyberFlash has discovered a problem in Internet Explorer that can be exploited by malicious attackers to trick users into deleting local folders.
The problem is that local network shares can be included in an ˝iframe˝, where only certain parts of the content are visible to the user. This can be exploited to trick users into deleting local folders, via an iframe referencing the local IP address and c$ resource.
Successful exploitation requires that the user selects the local folder icon and presses the delete key. Users may be tricked into doing so as they don´t know that the folder is a local one.
This problem, classified as ˝low risk˝, has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP2.
Oxygen3 24h-365d
by Panda Software
Member of IVSZ

Member of SZEK

Acer Affinity Gold partner

Dell Registered Partner
![]()
OKI System Shinrai Partner

XEROX Viszonteladó

APC megbízható szállító

EATON Authorized Partner

Cisco partner

Symantec Software Partner

ESET Partner
![]()
FUJITSU partner

LENOVO Premium Partner

IBM Business Partner

PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel