mjc
09-13-2002, 04:22 PM
We discovered that it is possible for an attacker to execute script on any page that contains <frame> or <iframe> elements, ignoring any protocol or domain restriction set forth by Internet Explorer. This means that an attacker can steal cookies from almost any site, access and change content in sites and in most cases also read local files and execute arbitrary programs on the client's machine (script in the "My Computer" zone).
GreyMagic Security
http://sec.greymagic.com/adv/gm010-ie/
Pretty easy fix for this one....disable "Navigate sub-frames across different domains" in Internet Options. And/or disable (or prompt) Active Scripting....
GreyMagic Security
http://sec.greymagic.com/adv/gm010-ie/
Pretty easy fix for this one....disable "Navigate sub-frames across different domains" in Internet Options. And/or disable (or prompt) Active Scripting....