The download function of Internet Explorer 6 SP1 allows remote attackers to obtain the cache directory name via an HTTP response with an invalid ContentType and a .htm file, which could allow remote attackers to bypass security mechanisms that rely on random names, as demonstrated by threadid10008.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2004-01-20 05:00
Updated : 2025-04-03 01:03
NVD link : CVE-2003-1028
Mitre link : CVE-2003-1028
CVE.ORG link : CVE-2003-1028
JSON object : View
Products Affected
microsoft
- ie
- internet_explorer
CWE