Forum Moderators: open
[securitytracker.com...]
Rafel Ivgi subsequently reported that the 'res:' protocol cannot be invoked from the Internet zone, preventing this flaw from being directly exploitable by remote users.
In short, this only works if you can get the user to download and view a page locally. And if you can get users to do that, there's far worse damage that can be done.