Advertisement
Promo

Become a member of the ZDNet UK community

Resources Downloads

Download Now

Microsoft XML 2.0 Core Services Vulnerability Patch MS02-008


License Free
Requirements Windows NT/2000
Downloads 92 Limitations None
Publisher Microsoft File Size 367k
Date added 02 Mar 2002 Check your speed

Microsoft XML Core Services (MSXML) includes the XMLHTTP ActiveX control, which allows web pages rendering in the browser to send or receive XML data via HTTP operations such as POST, GET, and PUT. The control provides security measures designed to restrict web pages so they can only use the control to request data from remote data sources.

A flaw exists in how the XMLHTTP control applies IE security zone settings to a redirected data stream returned in response to a request for data from a web site. A vulnerability results because an attacker could seek to exploit this flaw and specify a data source that is on the user's local system. The attacker could then use this to return information from the local system to the attacker's web site. An attacker would have to entice the user to a site under his control to exploit this vulnerability. It cannot be exploited by HTML email. In addition, the attacker would have to know the full path and file name of any file he would attempt to read. Finally, this vulnerability does not give an attacker any ability to add, change or delete data.

Download Now

Did you find this download useful?
11 out of 25 users found this download useful


People who downloaded this software also downloaded...

Super Socks5Cap 1.0.0.5

Allow network applications to operate through proxy servers.

More info +


Passware Kit Enterprise 8.1 build 2753

Recover lost and forgotten passwords for Excel, Word, Lotus Notes, RAR, WinZip, Access, Outlook, Acrobat, and VBA.

More info +


SoftProbe Analyzer 2.6 build 1.27

Perform regular analysis of individual workers' computer use.

More info +


Pop Cop 2.1.4.1

Block pop-ups and floating ads and keep your home page intact.

More info +


AdArmor 3.0.42

Eliminate ads and stop unsuitable content.

More info +


Super Ad Blocker 4.6

Block all forms of advertising, including pop-ups, Flash ads, and banner ads.

More info +


Active WebCam Deluxe 11.3

Broadcast MPEG-4 live video from your Webcam up to 30 frames per second.

More info +


Ad Arrest IE Popup Killer 2.1

Keep your Internet surfing free of pop-up ads.

More info +


Invisible Private Folder 2.1

Lock and hide your private files and folders.

More info +


BrowseControl 3.3

Restrict Internet access, filter URLs, block applications, filter ports.

More info +



Broadband Deals? Powered by Top 10 Broadband

150+ broadband packages

Compare 30+ mobile broadband deals

Mobile Broadband »

Download

Trend Micro Worry-Free Business Security Advanced

Trend Micro™ Worry-Free™ Business Security Advanced and Standard 6. #1 for Small Business Security

  • Downloads: 1,166
  • Requirements: Processor: Intel™ Pentium™ or AMD™. RAM: 256MB-1GB (operating system dependant). Disk space: 350MB. Web Browser: Microsoft™ Internet Explorer 6.0 or 7.0.
  • License:
  • Publisher:
  • Size: 0

Download Now

Video icon

Video

Google Chrome Special Report

All roads lead to Chrome

All roads lead to Chrome

Comment With its new browser, Google has finally taken its gaudy, chrome-plated, futuristic ray gun and pointed it straight at Microsoft's head

More Special Reports


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters