Cache Directory Disclosure Vulnerability in Internet Explorer 6 SP1

Cache Directory Disclosure Vulnerability in Internet Explorer 6 SP1

CVE-2003-1028 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

The download function of Internet Explorer 6 SP1 allows remote attackers to obtain the cache directory name via an HTTP response with an invalid ContentType and a .htm file, which could allow remote attackers to bypass security mechanisms that rely on random names, as demonstrated by threadid10008.

Learn more about our Web Application Penetration Testing UK.