[thelist] Critical security flaw with Windows IE and frames

Andy Warwick mailing.lists at creed.co.uk
Wed Sep 11 06:34:01 CDT 2002


>From The Register...

"Researchers have discovered that inadequate security restrictions in
Internet Explorer make it possible for an attacker to execute script on any
Web page that containing frames.

"Grey Magic Software describes the vulnerability as critical, a warning
backed up by several proof of concept demonstrations.

"Still no word from Microsoft on the issue, a fix for this particular
problem doesn't appear in a list of fixes included in Microsoft's release of
Service Pack 1 for IE6, which was released today."

<http://www.theregister.co.uk/content/55/27048.html >
<http://sec.greymagic.com/adv/gm010-ie/>

Ouch.

Andy W




More information about the thelist mailing list