>> Microsoft Internet Explorer FTP Command Injection Vulnerability
Title : Microsoft Internet Explorer FTP Command Injection Vulnerability VUPEN ID : VUPEN/ADV-2008-0870 CVE ID : CVE-2008-1368
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-03-13
Technical Description
A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by attackers to manipulate data or disclose sensitive information. This issue is caused by an input validation error when handling FTP URIs containing CRLF characters and trailing slashes, which could be exploited by attackers to inject arbitrary FTP commands in the security context of the current session by tricking a user into visiting a malicious web page.