First published: Thu May 05 2005(Updated: )
The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src property to the target filename and using Javascript to determine if the web page immediately stops loading, which indicates whether the file exists or not.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe SVG Viewer | =3.01 | |
Adobe SVG Viewer | =1.0 | |
Adobe SVG Viewer | =2.0 | |
Adobe SVG Viewer | =3.02 | |
Adobe SVG Viewer | =3.0 | |
All of | ||
Adobe SVG Viewer | <=3.02 | |
Internet Explorer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0918 is considered a moderate severity vulnerability due to its potential for file enumeration attacks.
To mitigate CVE-2005-0918, upgrade to Adobe SVG Viewer version 3.03 or later, which resolves the vulnerability.
CVE-2005-0918 impacts all versions of Adobe SVG Viewer up to 3.02 when run in Internet Explorer.
An attacker can use CVE-2005-0918 to determine the existence of arbitrary files on a victim's server.
Yes, CVE-2005-0918 specifically affects the Internet Explorer browser when interacting with Adobe SVG Viewer.