Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Internet_explorer | Microsoft | 4.0.1 (including) | 4.0.1 (including) | 
| Internet_explorer | Microsoft | 4.0.1-sp1 (including) | 4.0.1-sp1 (including) |