Microsoft Internet Explorer 5 - Classic Mode FTP Client Cross Domain Scripting

Author: Matthew Murphy
type: remote
platform: windows
port: 
date_added: 2003-06-04  
date_updated: 2012-11-15  
verified: 1  
codes:   
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 22728.txt  
source: https://www.securityfocus.com/bid/7810/info

The Microsoft Internet Explorer FTP indexing implementation could allow script code to be executed in the security zone of another FTP site. This vulnerability only exists when Internet Explorer FTP is used in "Classic Mode".

Any script would be executed with the permissions of the user running Internet Explorer.

ftp://%3cimg%20src%3d%22%22%20onerror%3d%22alert%28document%2eURL%29%22%3e.example.com/