The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability.
Software | From | Fixed in |
---|---|---|
microsoft / internet_explorer | 4.0 | 4.0.x |
microsoft / internet_explorer | 5.0 | 5.0.x |
microsoft / internet_explorer | 5.01 | 5.01.x |
microsoft / internet_explorer | 5.5 | 5.5.x |