Description
Microsoft Internet Explorer 4.0 through 7 allows remote attackers to determine the existence of local files that have associated images via a res:// URI in the src property of a JavaScript Image object, as demonstrated by the URI for a bitmap image resource within a (1) .exe or (2) .dll file.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/37638
Exploit x_refsource_misc
http://xs-sniper.com/blog/2007/07/20/more-uri-stuff-ies-resouce-uri/
Scores
EPSS
0.0750
EPSS Percentile
93.9%
Details
Status
published
Products (26)
microsoft/ie
4.x
microsoft/ie
5.0 sp1 (2 CPE variants)
microsoft/ie
5.0_ta3
microsoft/ie
5.x
microsoft/ie
6.0 sp1 (2 CPE variants)
microsoft/internet_explorer
4.0
microsoft/internet_explorer
4.0.1
microsoft/internet_explorer
4.1
microsoft/internet_explorer
4.5
microsoft/internet_explorer
5
... and 16 more
Published
Sep 12, 2007
Tracked Since
Feb 18, 2026