Launch Printer Friendly Page Security TechCenter > Security Bulletins > Microsoft Security Bulletin MS00-093

Microsoft Security Bulletin MS00-093

Patch Available for 'Browser Print Template' and 'File Upload via Form' Vulnerabilities

Originally posted: December 01, 2000

Summary

Microsoft has released a patch that eliminates four security vulnerabilities in Microsoft® Internet Explorer:

  • The "Browser Print Template" vulnerability, which could enable a malicious web site operator to take unauthorized actions on the computer of a user who visited her site.
  • The "File Upload via Form" vulnerability, which could enable a malicious web site operator to read files on a visiting user's computer.
  • New variants of the "Scriptlet Rendering" and "Frame Domain Verification" vulnerabilities, both of which could enable a malicious web site operator to read files on a visiting user's computer.

Affected Software:

  • Microsoft Internet Explorer 5.x

Vulnerability Identifiers

General Information

Technical details

Frequently asked questions

Patch availability

Other information:

Acknowledgments

Microsoft thanks the following people for working with us to protect customers:

  • Warren R. Greer for reporting the "Browser Print Template" issue to us.
  • Juan Carlos Garcia Cuartango (www.s21sec.com) and Vladimir Sulc, jr., (www.microrisc.cz) for reporting the "File Upload via Form" vulnerability to us.

Support: This is a fully supported patch. Information on contacting Microsoft Product Support Services is available at http://support.microsoft.com/contactussupport/?ws=support.

Security Resources: The Microsoft TechNet Security Web Site provides additional information about security in Microsoft products.

Disclaimer:

The information provided in the Microsoft Knowledge Base is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.

Revisions:

  • December 01, 2000: Bulletin Created.