CVE Database
/

CVE-2014-1816

Back to search

CVE-2014-1816

Published: Jun 11, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

Microsoft XML Core Services (aka MSXML) 3.0 and 6.0 does not properly restrict the information transmitted by Internet Explorer during a download action, which allows remote attackers to discover (1) full pathnames on the client system and (2) local usernames embedded in these pathnames via a crafted web site, aka "MSXML Entity URI Vulnerability."

VendorProductVersions

n/a

n/a

affected
n/a

References

MS14-033
vendor-advisory
x_refsource_MS
67895
vdb-entry
x_refsource_BID
58538
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now