vendor:
Internet Explorer
by:
Unknown
5.5
CVSS
MEDIUM
Resource Existence Determination
200
CWE
Product Name: Internet Explorer
Affected Version From: Internet Explorer 5.0
Affected Version To: Internet Explorer 6.0
Patch Exists: YES
Related CWE: CVE-2004-1061
CPE: a:microsoft:internet_explorer
Platforms Tested: Windows
2004
Microsoft Internet Explorer Resource Existence Determination Weakness
An attacker can use an IFRAME that is accessible within the same domain and change its URI to the location of a file or directory. The attacker can then determine the existence of the resource by the error message returned by Internet Explorer. This weakness can then allow the attacker to carry out other attacks against a vulnerable computer.
Mitigation:
It is recommended to apply the latest security patches and updates for Internet Explorer. Additionally, users should exercise caution when visiting unknown or untrusted websites.