SECUNIA ALERTED users to three holes in the Microsoft Browser Client Tool, which has the less sexy cognomen of w3who.dll. The firm said the holes, discovered by Nicolas Gregoire, allow wicked people to conduct cross site scripting attacks or to compromise vulnerable systems. The first hole means that invalid input passed to ISAPI extension is not "sanitised" properly before being returned as error messages. This can mean people can execute arbitrary HTML and script code in a browser session at a vulnerable web site.