The download function of Internet Explorer 6 SP1 allows remote attackers to obtain the cache directory name via an HTTP response with an invalid ContentType and a .htm file, which could allow remote attackers to bypass security mechanisms that rely on random names, as demonstrated by threadid10008.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2004-01-19 21:00
Updated : 2021-07-23 05:55
NVD link : CVE-2003-1028
Mitre link : CVE-2003-1028
JSON object : View
CWE
Products Affected
microsoft
- internet_explorer
- ie