← Back

CVE-2012-6502

nvd nist
Published: Jan 22, 2013Modified: Apr 29, 2026

JSON object

Loading...
2.6
Vector
AV:N/AC:H/Au:N/C:P/I:N/A:N
Exploitability: 4.9 / Impact: 2.9
Source: NVD

Description

Microsoft Internet Explorer before 10 allows remote attackers to obtain sensitive information about the existence of files, and read certain data from files, via a UNC share pathname in the SRC attribute of a SCRIPT element, as demonstrated by reading a name-value pair from a local file via a \\127.0.0.1\C$\ sequence.

Affected (6)

1 product
Internet Explorer
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 6
Version 6 sp1
Version 7.0.5730
Version 7
Version 8
Version 9

References (2)

Timeline

No history available yet.