Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: [Full-Disclosure] Internet explorer 6 on windows XP allows exection of arbitrary code Sep 11 2003 11:02PM
Thor Larholm (thor pivx com)
The new addition here is abusing how you are able to load a ressource file,
residing in a local security zone, into a window object. Service Pack 1 for IE6
did a lot to deter this on most regular window objects, but should have extended
that effort to searchpanes as well. Seeing as the content of a...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus