Publisher's Description
From Microsoft:
Microsoft XML Core Services (MSXML) includes the XMLHTTP ActiveX control, which allows web pages rendering in the browser to send or receive XML data via HTTP operations such as POST, GET, and PUT. The control provides security measures designed to restrict web pages so they can only use the control to request data from remote data sources.
A flaw exists in how the XMLHTTP control applies IE security zone settings to a redirected data stream returned in response to a request for data from a web site. A vulnerability results because an attacker could seek to exploit this flaw and specify a data source that is on the user's local system. The attacker could then use this to return information from the local system to the attacker's web site. An attacker would have to entice the user to a site under his control to exploit this vulnerability. It cannot be exploited by HTML email. In addition, the attacker would have to know the full path and file name of any file he would attempt to read. Finally, this vulnerability does not give an attacker any ability to add, change or delete data.
More Popular Corporate Security Software downloads
- Folder Guard
1,657 downloads
- L0phtCrack Password Auditing & Recovery
945 downloads
- USB Lock RP
218 downloads
- USB Manager
214 downloads
- Passware Kit Enterprise
209 downloads
-
All versions:
3.4 starsout of 10 votes
-
Current version:
3.2 starsout of 9 votes
-
My rating:
Write review
Results 1-7 of 7
-
"took less than a minute"
Version: Microsoft XML 3.0 Core Services Vulnerability Patch MS02-008
Summary
Don't know how ell this will work, but it took less than 2 minutes to download over my phone modemonly
-
"You make the Choise weather it is worth it or not"
Version: Microsoft XML 3.0 Core Services Vulnerability Patch MS02-008
Summary
Well you make the choise: Download it, and wait a long time, or get a T1 line and download it in seconds!
-
"NO GOOD "SCARY""
Version: Microsoft XML 3.0 Core Services Vulnerability Patch MS02-008
Summary
WOULD NOT DOWNLOAD,HAVE DIAL UP NETWORK AND NORTON ANTI-VIRUS ALREADY.MAYBE THIS HAS TO DO WITH IT.TRIED DOWNLOADING BUT GOT ERRORS....FROZE....
-
"installed fine for me"
Version: Microsoft XML 3.0 Core Services Vulnerability Patch MS02-008
Summary
installed very simply, downloaded fast(in seconds),of course I dont use dial up services though. Regardles it worked fine
-
"What download...Ain't working !"
Version: Microsoft XML 3.0 Core Services Vulnerability Patch MS02-008
-
"WOULD NOT WORK"
Version: Microsoft XML 3.0 Core Services Vulnerability Patch MS02-008
Summary
Could not get the site to download, kept getting the error page and then could not find the site on the homepage, big waste of time
-
"hmmm"
Version: Microsoft XML 3.0 Core Services Vulnerability Patch MS02-008
Summary
this package does not want to download/couldn't find the site

