Overview
A vulnerability exists in the DHTML Edit Control for IE5 that allows arbitrary local files to be uploaded to a web server.
Description
DHTML Edit is an activex control that is marked safe-for-scripting. This control can be embedded in a website, and permit local files to be remotely uploaded to the malicious server, if the file location is known. The ClassID of the vulnerable dhtmled.ocx activex control is {2D360201-FFF5-11D1-8D03-00A0C959BC0A}. According to the Microsoft Security Bulletin: |
Impact
Attacker can upload files with known names from the local hard drive to the server, and can read information that user supplies to the control. |
Solution
Apply the patch from Microsoft's Security Bulletin MS99-011. The patch changes control to restrict actions based on the domain. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was reported to Microsoft by Juan Carlos Cuartango of Spain.
This document was written by Jason A Rafail.
Other Information
CVE IDs: | CVE-1999-0487 |
Severity Metric: | 1.98 |
Date Public: | 1999-04-21 |
Date First Published: | 2002-10-01 |
Date Last Updated: | 2002-10-16 19:00 UTC |
Document Revision: | 14 |