TCH-Thomas Posted December 17, 2004 Posted December 17, 2004 (edited) From Slashdot (http://it.slashdot.org/article.pl?sid=04/12/16/2314224&from=rss): Jimmy M. writes "A new vulnerability has been announced in Internet Explorer, also affecting XP SP2, which can very easily be exploited by a malicious web site to completely spoof the address bar. The vulnerability is very similar to another vulnerability disclosed just about a year ago called the '%00' vulnerability, which also was widely exploited by phishers. A demonstration is also available."Secunia writesThe vulnerability is caused due to an error in the DHTML Edit ActiveX control when handling the "execScript()" function in certain situations. This can be exploited to execute arbitrary script code in a user's browser session in context of an arbitrary site. The test mentioned can be found at: http://secunia.com/internet_explorer_cross-site_scripting_vulnerability_test/ Edit: Added the info from secunia. Edited December 17, 2004 by TCH-Thomas Quote
arvind Posted December 17, 2004 Posted December 17, 2004 Wow scary stuff, thank god I use Firefox ! Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.