Microsoft has released a series of follow-on fixes to its Internet Explorer patch of last week that allow Web sites and enterprises to continue to use the XMLHTTP control for authentication. Last Monday, Microsoft rolled out a patch for IE to plug a hole that could allow an attacker to “spoof” a URL by disguising a malicious site as a legitimate address showing in the Web browser's address bar.
|