Secunia Logo
 
CVE Reference: CVE-2007-4356
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-4356

Description:
Microsoft Internet Explorer 6 and 7 embeds FTP credentials in HTML files that are retrieved during an FTP session, which allows context-dependent attackers to obtain sensitive information by reading the HTML source, as demonstrated by a (1) .htm, (2) .html, or (3) .mht file.

CVE Status:
Candidate

References:

SAID
  Secunia Advisory: SA26427

OSVDB
  36400

MISC
  http://blog.washingtonpost.com/securityfix/2007/08/ftp_files_expose_web_site_cred.html


Return to the previous page.