Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.
|
|||||||
Download Now:
dragDrop invocation IE vulnerability
|
|
Thread Tools | Search this Thread |
|
#1
|
||||
|
||||
|
dragDrop invocation IE vulnerability
We already knew pressing the back button on IE is dangerous
(http://online.securityfocus.com/archive/1/267561) So it wont come as a total shock that so is clicking a link The problem lies in the dragdrop method that was added as a method on nearly all HTML elements in ie5.5 This method makes any element act like its being dragged. It is possible to abuse this behaviour to drop text in a html upload control thus allowing you to read any file from an unsuspecting users harddisk.Would you like to know more? Thanks PivX. |
![]() |
| Similar Topics | ||||
| Topic | Replies | Forum | ||
IE 7 & Adobe PDF vulnerability
|
3 | Virus and Malware Removal | ||
Could someone please explain this vulnerability?
|
2 | Windows OS | ||
Sasser virus has vulnerability
|
2 | General Discussion | ||
Vulnerability in MSN Messenger
|
0 | General Discussion | ||
Microsoft patches 15 IE vulnerability
|
0 | General Discussion | ||
| Thread Tools | Search this Thread |
|
|
All times are GMT -4. The time now is 04:06 AM.


The problem lies in the dragdrop method that was added as a method on nearly all HTML elements in ie5.5 This method makes any element act like its being dragged. It is possible to abuse this behaviour to drop text in a html upload control thus allowing you to read any file from an unsuspecting users harddisk.
IE 7 & Adobe PDF vulnerability