vendor:
Internet Explorer
by:
SecurityFocus
7.5
CVSS
HIGH
Cascading Style-Sheets (CSS) Interpreter for Microsoft Internet Explorer
200
CWE
Product Name: Internet Explorer
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2002-0392
CPE: N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2002
Cascading Style-Sheets (CSS) Interpreter for Microsoft Internet Explorer
It is possible to use the cssText property of the styleSheet to read portions of files that exist on an arbitrary web user's system. Successful exploitation will cause the CSS interpreter used by Internet Explorer to read portions of text if the targetted file contains a '{' character. An attacker may exploit this via a malicious webpage to disclose sensitive information contained in (almost) arbitrary files that exist on a web user's system.
Mitigation:
Microsoft Security Bulletin MS02-023 includes patches for this vulnerability.