Another Cuartango Security Hole (an Internet Explorer hole).
21 Oct. 1998
Summary
Internet Explorer prohibits VBScripts from executing with Full Control access without the user's permission, this permission is given by the user simply clicking on the "YES" button in the security alert dialog. By creating a false dialog above the security alert dialog, while making sure the security dialog's "YES" button is still visible, you can make the user click on the "YES" button without being "afraid".
Internet Explorer was found to have a possible security breach. When Internet Explorer sees that a VBScript exists inside the HTML, it will show a security alert dialog asking you to confirm that the VBScript inside the HTML is "ok". By clicking on the "YES" button you give the VBScript full control to your machine.
The problem consists of the possibility of creating a smaller dialog above the security dialog with a "friendly" message making it "easier" for the user to click on the "YES" button.