MSMVPS.COM
The Ultimate Destination for Blogs by Current and Former Microsoft Most Valuable Professionals.

Internet Explorer : Cross-Site Scripting vulnérabilité

L'XPditif, Le weblog Bleu-Blanc-Belge qui décoince ...

Syndication

Cette vulnérabilité est due au contrôle ActiveX DHTML Edit lors du traitement de la fonction "execScript()" dans certaines situations. Elle peut être exploitée pour exécuter du code malveillant depuis un site spécialement conçu.

Un POC par Secunia

Source : secunia.com

JacK

 


Posted Dec 19 2004, 12:43 PM by Christian Hougardy (Wygwam Team)


Copyright © is the original authors. Blog site is an independent site not sponsored by Microsoft. The Yoda blog server and the Brianna SQL server would like to thank www.ownwebnow.com and www.exchangedefender.com. They wouldn't be here and broadcasting without the generosity of Vlad Mazek and his companies.

Powered by Community Server (Commercial Edition), by Telligent Systems