AplusWebMaster
Topic Starter
FYI…
- http://www.theinquirer.net/?article=22649
19 April 2005
"…An attacker may execute any command as the logged-on user simply by having the user select a file. Executing the file is not required for exploitation, all it takes is selecting an innocent-looking file - maybe to delete it. The exploit applies to certain versions of Windows 2000. Since Microsoft still hasn't patched the hole, you'll have to have a look at the GreyMagic page for a workaround…"
- http://www.greymagic.com/security/advisories/gm015-ie/
19 Apr 2005
"…Solution:
Until a patch becomes available, disable the Web View by going to: Tools -> Folder Options -> Select 'Use Windows classic folders'…"

- http://www.theinquirer.net/?article=22649
19 April 2005
"…An attacker may execute any command as the logged-on user simply by having the user select a file. Executing the file is not required for exploitation, all it takes is selecting an innocent-looking file - maybe to delete it. The exploit applies to certain versions of Windows 2000. Since Microsoft still hasn't patched the hole, you'll have to have a look at the GreyMagic page for a workaround…"
- http://www.greymagic.com/security/advisories/gm015-ie/
19 Apr 2005
"…Solution:
Until a patch becomes available, disable the Web View by going to: Tools -> Folder Options -> Select 'Use Windows classic folders'…"