main
Report a problem

Internet Explorer Hit by Major XSS Bug

Mr magoo   on 17 December 2004 - 14:18 · 62 comments & 6771 views

Advertisement (Why?)
Security advice firm Secunia has released information concerning a new flaw with Microsoft's web browser, Internet Explorer.

The exploit allows cross site scripting attacks to be performed on users. In the scenario that Secunia have published, users can follow a link to xyz.com, have xyz.com in the address bar yet have content being fed to the browser from another site. Clicking on the "Pad-lock" SSL icon in the bottom corner of internet explorer also reveals xyz.com.

The problem is caused by "DHTML Edit ActiveX control when handling the "execScript()" function in certain situations. This can be exploited to execute arbitrary script code in a user's browser session in context of an arbitrary site". The issue affects the most recent releases of Internet Explorer 6.0, including Service Pack 2 patched systems. To avoid the exploit affecting you, it's advised that you disable ActiveX. Microsoft have yet to comment or release a patch for the problem.

Other browsers are not affected.

View: Secunia Advisory

Post a comment · Send to friend Comments · There are 62 additional comments
(1 reply) #1 on 01 Jan 1970 - 00:00
#1.1 vetMr magoo on 17 Dec 2004 - 14:34
For pitties sake - i imagine the posts were deleted because they were offense or broke our rules. If you've got a problem with any action, you need to take it up at the time with the moderator that did it. Please continue this via PM.

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)