Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft Internet Explorer User Security Confirmation Bypass Vulnerability

No exploit is required to leverage this issue. Reportedly, a comment of the following form when placed between the '<!DOCTYPE>' and '<HTML>' tags will trigger this issue:

<!-- saved from usr=(XXXX)URL -->

where 'URL' is a URL string such as 'http://www.example.com' and 'XXXX' is a four-digit number that corresponds to the number of characters in the URL string.







 

Privacy Statement
Copyright 2009, SecurityFocus