[prev in list] [next in list] [prev in thread] [next in thread] 

List:       bugtraq
Subject:    Re: Netscape Communicator 4.5 can read local files
From:       "Todd C. Campbell" <toddc () SERV01 ! NET-LINK ! NET>
Date:       1998-11-30 15:29:59
[Download RAW message or body]

Trev wrote:

> At 12:48 PM 11/25/98 -0500, Ben Collins wrote:
> >If some one here can setup a webpage, send me the URL, have that page read
> >the file '/test.txt' from my hardrive and then that person send the
> >contents to this list, I will believe. Otherwise I think this whole
> >hysteria over 'unforseen' dangers should stop.
>
> I've whipped up a couple of demos of this bug that send the contents to a
> cgi.  There is a windows version that I know works, and a unix version I
> can't test because my linux box is down (it's a hardware thing).  This is
> for anyone who has doubts....
>
> http://www.kics.bc.ca/~trev/cgi-bin/test.html (Windoze)
>
> http://www.kics.bc.ca/~trev/cgi-bin/test-unix.html (UNIX)
>
> And yes, it can email it to you if you like :)
>
> Trev


Does anybody know what Netscape's stance is on this, do they have a timeline?

-Todd

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic