Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.
| Software | From | Fixed in |
|---|---|---|
| microsoft / internet_explorer | 4.0.1 | 4.0.1.x |
| microsoft / internet_explorer | 4.0.1-sp1 | 4.0.1-sp1.x |