XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.
| Software | From | Fixed in |
|---|---|---|
| microsoft / sql_server | 2000-sp2 | 2000-sp2.x |
| microsoft / sql_server | 2000 | 2000.x |
| microsoft / xml_core_services | 2.6 | 2.6.x |
| microsoft / sql_server | 2000-sp1 | 2000-sp1.x |
| microsoft / xml_core_services | 3.0 | 3.0.x |
| microsoft / xml_core_services | 4.0 | 4.0.x |
| microsoft / internet_explorer | 6.0 | 6.0.x |
| microsoft / windows_xp | - | - |