Cache Directory Disclosure Vulnerability in Internet Explorer 6 SP1
CVE-2003-1028 · MEDIUM Severity
AV:N/AC:L/AU:N/C:P/I:N/A:N
The download function of Internet Explorer 6 SP1 allows remote attackers to obtain the cache directory name via an HTTP response with an invalid ContentType and a .htm file, which could allow remote attackers to bypass security mechanisms that rely on random names, as demonstrated by threadid10008.
Learn more about our Web Application Penetration Testing UK.