March 11, 2008
10:32 pm

A flaw in the way Microsoft's Internet Explorer browser processes FTP commands could let attackers steal or erase data from a victim's FTP site.

The bug, which affects users of IE 6 and the unsupported IE 5 browser, gives an attacker a way of hijacking the victim's FTP sessions. But a successful attack would be very hard to pull off and would only work in very precise, targeted attacks, security experts said.

The attacker would need to know the victim's username on the FTP server and the victim would have to already be logged into the server, using IE. Under those conditions, the victim could be sent a malicious FTP link that would then execute commands on the victim's FTP server.

View: Rapid7 Security Advisory |  Full Article

Internet Explorer, IE, Vulnerability, Flaw, FTP, Exploit

Loading

Contextual Related Posts:

No followup yet

Leave a Response

Comment Preview
« Windows SBS 2008 75 users productWindows Server 2008: What’s new and improved in IPsec »
Feed Icon

Subscribe via RSS or email: