[Home] [By Thread] [By Date] [Recent Entries]

  • From: "Didier PH Martin" <martind@n...>
  • To: "'XML Dev'" <xml-dev@i...>
  • Date: Tue, 14 Dec 1999 14:41:33 -0500

Hi,

I tought this may be interesting.

Cheers
Didier PH Martin
mailto:martind@n...
http://www.netfolder.com 

-----Original Message-----
From: owner-xmledi-list@l...
[mailto:owner-xmledi-list@l...]On Behalf Of David RR
Webber
Sent: Friday, December 03, 1999 1:55 AM
To: The XML/EDI Group
Subject: FWD: IE5.0 security warning


 
dave thought you might like to read this one - first time I've seen xml
implicated in a security threat...

* INTERNET EXPLORER 5.0 XML REDIRECTS
Georgio Guninski reported a problem with Internet Explorer (IE) 5.0
under Windows NT 4.0 and Windows 95. According to the report, IE 5.0
has a problem with the way it handles HTTP redirects in Extensible
Markup Language (XML) objects. The problem unnecessarily exposes a
user's local file.
   When a user embeds an XML document within an HTML document, IE 5.0
doesn't handle the HTTP redirects properly, thereby allowing access to
the domain of the embedded XML document.
   http://www.ntsecurity.net/go/load.asp?iD=/security/IE54.htm

==========================================
XML/EDI Group members-only discussion list
Homepage =  http://www.xmledi.com

Brought to you by: Online Technologies Corporation
                  Home of BizServe - www.bizserve.com

TO UNSUBSCRIBE: Send email to <xmledi-list-request@l...>
               Leave the subject blank, and
               In the body of the message, enter ONLY: unsubscribe

Questions/requests should be sent to: owner-xmledi-list@b...
To join the XML/EDI Group complete the form located at:
http://www.geocities.com/WallStreet/Floor/5815/mail1.htm



xml-dev: A list for W3C XML Developers. To post, mailto:xml-dev@i...
Archived as: http://www.lists.ic.ac.uk/hypermail/xml-dev/ and on CD-ROM/ISBN 981-02-3594-1
To unsubscribe, mailto:majordomo@i... the following message;
unsubscribe xml-dev
To subscribe to the digests, mailto:majordomo@i... the following message;
subscribe xml-dev-digest
List coordinator, Henry Rzepa (mailto:rzepa@i...)



Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member