CENTER.HU groups
CENTER.HU address

User:

Guest

www.center.hu / Archive / Security news / march, 2006 / Internet Explorer Folder Deletion 

Internet Explorer Folder Deletion

Internet Explorer Folder Deletion

Madrid, March 1, 2006 - The company CyberFlash has discovered a problem in Internet Explorer that can be exploited by malicious attackers to trick users into deleting local folders.

The problem is that local network shares can be included in an ˝iframe˝, where only certain parts of the content are visible to the user. This can be exploited to trick users into deleting local folders, via an iframe referencing the local IP address and c$ resource.

Successful exploitation requires that the user selects the local folder icon and presses the delete key. Users may be tricked into doing so as they don´t know that the folder is a local one.

This problem, classified as ˝low risk˝, has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP2.

Oxygen3 24h-365d
by Panda Software

Back




Copyright © CENTER.HU Ltd, 2000-2010. All rights reserved

sitemap | privacy policy |

copyrights | new pages |

terms of purchase | contact us


PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel