Jump to content

Internet Explorer Frame Injection Vulnerability


NeonWizard
 Share

Recommended Posts

Secunia Advisory: SA11966

Release Date: 2004-06-30

Moderately critical

Impact: Spoofing

Where: From remote

Software: Microsoft Internet Explorer 5.01

Microsoft Internet Explorer 5.5

Microsoft Internet Explorer 6

Description:

http-equiv has discovered a 6 year old vulnerability in Microsoft Internet Explorer, allowing malicious people to spoof the content of websites.

The problem is that Internet Explorer fails to stop a malicious website from loading arbitrary content in an arbitrary frame in another browser window. An example has been posted, which shows arbitrary content in a frame on windowsupdate.microsoft.com.

Solution:

Do not visit or follow links from untrusted websites.

Use another browser.

Read Security Bulletin

Just another reason people need to get rid of IE. Waht si it now? 3 unpatched vulnerabilities?

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy