Vulnerability in Microsoft XML Core Services Leading to File Access
CVE-2002-0057
Currently unrated
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 8 March 2002
What is CVE-2002-0057?
The vulnerability in Microsoft XML Core Services stems from the XMLHTTP control's inadequate handling of Internet Explorer Security Zone settings. This flaw enables remote attackers to exploit the functionality by designating a local file as an XML Data Source, which permits unauthorized access to arbitrary files on the affected system. This concern emphasizes the importance of robust security practices and proper configuration of web applications to mitigate such risks.