|
Brought to you by:
Suppliers of:
|
|
|
| |
| A Cross Site Scripting vulnerability has been discovered in Internet Explorer's about:blank page. The vulnerability allows attackers to cause the product to execute arbitrary HTML and/or JavaScript. |
| |
Credit:
The information has been provided by Lorenzo Hernandez Garcia-Hierro .
|
| |
Vulnerable systems:
* Internet Explorer version 6.0.2600.x (without SP1)
* Internet Explorer version 5.0.x
* Internet Explorer version 4.x
* Internet Explorer version 3.x
Immune systems:
* Internet Explorer version 6.0.2600.x with SP1
By passing a specially crafted URL to the Internet Explorer, a remote attacker can cause the product to return arbitrary HTML and/or JavaScript.
Examples:
about:blank%20< script>alert('8-D uhh !');</script>
about:blank%20< iframe src="about:blank%20<h1>;- )"></iframe>
about:blank%20< h1>XSS is behind you...</h1>
|
|
|
|
|