CVE-2007-4356: Critical severity Microsoft Internet Explorer vulnerability
Microsoft Internet Explorer 6 and 7 embeds FTP credentials in HTML files that are retrieved during an FTP session, which allows context-dependent attackers to obtain sensitive information by reading the HTML source, as demonstrated by a (1) .htm, (2) .html, or (3) .mht file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4356?
CVE-2007-4356 is considered to have a moderate severity level due to the potential exposure of sensitive information.
How do I fix CVE-2007-4356?
The recommended fix for CVE-2007-4356 is to upgrade to a later version of Internet Explorer that does not contain this vulnerability.
What versions of Internet Explorer are affected by CVE-2007-4356?
CVE-2007-4356 affects Microsoft Internet Explorer versions 6 and 7.
What type of information can be exposed by CVE-2007-4356?
CVE-2007-4356 can expose FTP credentials embedded in HTML files during an FTP session.
Can CVE-2007-4356 be exploited remotely?
CVE-2007-4356 can be exploited by context-dependent attackers with access to the HTML source.