source: https://www.securityfocus.com/bid/25836/info
Microsoft Internet Explorer is prone to an information-disclosure vulnerability that allows attackers to gain access to the contents of arbitrary files.
This issue stems from a design error resulting from the improper handling of form fields.
This issue is similar to the one described in BID 24725 (Mozilla Firefox OnKeyDown Event File Upload Vulnerability).
# based upon Hong's exploit:
# http://sla.ckers.org/forum/read.php?3,13142