ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Join ZDNet's roundtable on datacentres

Resources Downloads

Download Now

Microsoft XML 3.0 Core Services Vulnerability Patch MS02-008


License Free
Requirements Windows NT/2000
Downloads 117 Limitations None
Publisher Microsoft File Size 550k
Date added 02 Mar 2002 Check your speed

Microsoft XML Core Services (MSXML) includes the XMLHTTP ActiveX control, which allows web pages rendering in the browser to send or receive XML data via HTTP operations such as POST, GET, and PUT. The control provides security measures designed to restrict web pages so they can only use the control to request data from remote data sources.

A flaw exists in how the XMLHTTP control applies IE security zone settings to a redirected data stream returned in response to a request for data from a web site. A vulnerability results because an attacker could seek to exploit this flaw and specify a data source that is on the user's local system. The attacker could then use this to return information from the local system to the attacker's web site. An attacker would have to entice the user to a site under his control to exploit this vulnerability. It cannot be exploited by HTML email. In addition, the attacker would have to know the full path and file name of any file he would attempt to read. Finally, this vulnerability does not give an attacker any ability to add, change or delete data.

Download Now

Did you find this download useful?
13 out of 26 users found this download useful


People who downloaded this software also downloaded...

SolidShare 2.6.11

Connect anyone on your network to the Internet with one ISP account and one modem.

More info +


SpyWall Anti-Spyware 1.4.3.1

Remove spyware and keep them out with a browser sandbox.

More info +


Cute Password Manager 2008.1.3.8

Log into Web sites and fill forms with just a few mouse clicks.

More info +


DoNotDisturb 2.3

Block access to selected programs so you can concentrate on your work.

More info +


n-Pass2Go 2.7.0.465

Store and manage your passwords and encrypted data on any removable device.

More info +


EasyCryptor 1

Encrypt and decrypt any files and send results to your e-mail address.

More info +


Child Computer Lock 1.6

Protect your privacy by locking your computer.

More info +


Anonymity Gateway 2.5

Mask your real IP while surfing and erase traces of online activity.

More info +


CommandCenter-NOC 6

Perform asset management, security monitoring, bandwidth analysis, and reporting for your network.

More info +


Watch N Catch 1.0

Protect your assets with an IP-based video surveillance system.

More info +




Download

Embarcadero Power SQL

Embarcadero PowerSQL simplifies SQL development for application developers with many features for improving productivity and reducing errors.

  • Downloads: 4,554
  • Requirements:
  • License: Vendor registration required
  • Publisher: Embarcadero
  • Size: 0

Download Now

Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

3 comments

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

1 comment

Featured Talkback

It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link

DOWNLOAD

Security Essentials

Security Downloads

There are masses of security suites out there for small businesses. Here's a selection to get you started

Editor’s Rating
1 Norton 360™
2 AVG Anti-Virus Free Edition Rating: 10
3 PC Tools AntiVirus Free Edition
4 Kaspersky Internet Security

See All Software

In association with Symantec