Internet Explorer 6.0 SP1 + Win2k SP4 (up to date) local file detection advisory and exploit which uses the sysimage:// protocol to allow websites to determine which software is installed. Online demonstration available here.
d04eeb9baa76349ffdd543832c8a102a1200881700755affafb7ea344f65c2e6