Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Computer Security > Microsoft Internet Explorer Vulnerability

Reply
Thread Tools

Microsoft Internet Explorer Vulnerability

 
 
imhotep
Guest
Posts: n/a
 
      06-28-2006
"Microsoft Internet Explorer is prone to an information-disclosure
vulnerability because it fails to properly enforce cross-domain policies.

This issue may allow attackers to access arbitrary websites in the context
of a targeted user's browser session. This may allow attackers to perform
actions in web applications with the privileges of exploited users or to
gain access to potentially sensitive information. This may aid attackers in
further attacks.

Microsoft Internet Explorer version 6.0 on Windows XP SP2 is vulnerable to
this issue; other versions may also be affected."

http://www.securityfocus.com/bid/18682/discuss

-- Imhotep


--
*************************************
Pass a Net Neutrality Law in the US!!!!

Save the Internet:
http://www.savetheinternet.com/

Its our net:
http://www.itsournet.org/

*************************************
 
Reply With Quote
 
 
 
 
Sebastian Gottschalk
Guest
Posts: n/a
 
      06-28-2006
imhotep wrote:
> "Microsoft Internet Explorer is prone to an information-disclosure
> vulnerability because it fails to properly enforce cross-domain policies.


MUAHAHA!

IE cannot ever enforce cross-domain policies by design! Lie Di Yu has
pointed that out back in 2004 and nothing has been changed since then.

<http://www.safecenter.net/crosszone/ie/SaveRef.htm>
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Internet Explorer 8: C:\Program Files\Internet Explorer\iexplore.exe vs C:\Program Files (x86)\Internet Explorer\iexplore.exe Nathan Sokalski Windows 64bit 16 02-22-2010 08:31 AM
Microsoft Internet Explorer Malformed HTML Parsing Denial of Service Vulnerability Imhotep Computer Security 16 06-03-2006 02:30 AM
Microsoft Internet Explorer JavaScript OnLoad Handler Remote Code Execution Vulnerability Imhotep Computer Security 6 12-21-2005 06:14 AM
Microsoft Internet Explorer COM Object Instantiation Memory Corruption Vulnerability Imhotep Computer Security 2 12-15-2005 03:03 PM
Microsoft Internet Explorer Scrollbar-Base-Color Partial Denial Of Service Vulnerability kayodeok HTML 2 10-25-2003 09:20 PM



Advertisments