01642 06 11 11 Arrange Call

Arbitrary File Reading Vulnerability in XMLHTTP Control

CVE-2002-0057 · MEDIUM

CVE-2002-0057

XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.

Learn more about our Web Application Penetration Testing UK.