Researchers have discovered that inadequate security restrictions in Internet Explorer make it possible for an attacker to execute script on any Web page that containing frames. Grey Magic Software describes the vulnerability as critical, a warning backed up by several proof of concept demonstrations. Because of the way frames (and iframes) are handled by IE version 5.5 and above, attackers are able to get to all sorts of mischief with minimal effort.
|