TITLE: Test IE CSS File Disclosure Vulnerability

DATE: 2002-04-02

DESCRIPTION:

Uses the "cssText" property of included CSS file to retrieve the file content.

This vulnerability allows the attacker to get local files content if they contain a '{' character.


Try the vulnerability:

1-Create a small text file which contains curly braces

2-Store it under "c:\testie.txt" name

3-Click on the button below


Originally posted at http://sec.greymagic.com/adv/gm004-ie