[Full-disclosure] MSIE7 browser entrapment vulnerability (probably Firefox, too)

Michal Zalewski lcamtuf at dione.ids.pl
Mon Feb 26 18:11:15 GMT 2007


On Fri, 23 Feb 2007, Jeffrey Katz wrote:

> Just checked on IE 7.0.5730.11 -- doesn't exhibit problem.

Most certainly does; you might have scripting disabled, or be
experiencing some other anomaly, but for much of the population, the
attack works as advertised on that version.

/mz




Full-Disclosure is hosted and sponsored by Secunia.