vendor:
Internet Explorer
by:
SecurityFocus
7.5
CVSS
HIGH
Conflicting HTTP Headers
20
CWE
Product Name: Internet Explorer
Affected Version From: Microsoft Internet Explorer 5.0
Affected Version To: Microsoft Internet Explorer 6.0
Patch Exists: YES
Related CWE: CVE-2002-0649
CPE: a:microsoft:internet_explorer
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2002
Microsoft Internet Explorer Conflicting HTTP Headers Vulnerability
An issue exists in the way Microsoft Internet Explorer handles conflicting information in some HTTP headers used to describe non-HTML content. A malicious web server may provide content with misleading values in the content-type and content-disposition headers. Under some circumstances, the result may be that IE will automatically download and execute attacker-supplied programs. It has been demonstrated that this vulnerability can be exploited when Windows Media Player 6.4 or 7.1 is installed on the system. This vulnerability may also be exploited through HTML formatted email.
Mitigation:
Users should exercise caution when downloading and executing files from untrusted sources. It is also recommended that users disable the 'Allow active content to run in files on My Computer' option in the Internet Options Security tab.