Latest Comments
"i like this network."
by liao niandong | Sep 7, 2008 7:27 PM
 
"hi.. i like google chrome. I need to know if in future, google is willing to upgrade google ..."
by george s | Sep 7, 2008 1:52 AM
 
"I urge every business person and IT person, management or staff, to get hold of a copy of "I.T. ..."
by John Franks | Sep 6, 2008 1:20 AM
 
"test for intresting"
by cocoboy | Sep 5, 2008 5:39 PM
 
""Google arrived on the browser scene with the launch of Chrome"... Seems a bit misplaced to ..."
by Jeme | Sep 5, 2008 12:33 AM

Security experts warn of IE6 flaw

  • Email a Friend
  • Print Page
Security experts warn of IE6 flaw
By Shaun Nichols
Jun 30, 2008 10:02 AM
Tags: IE6 | vulnerabilities | & | exploits | Explorer | Internet
Security experts have warned of a new vulnerability in Microsoft's Internet Explorer 6.

The US Computer Emergency Response Team (US-Cert) said that the flaw lies in the way the browser handles attempted cross-site scripting attacks.

When code is embedded within a specially crafted HTML document, the security protections will not function properly, leaving the user open to attack.

US-Cert believes that an attacker could execute a cross-domain scripting attack and steal cookies and security credentials without any warning to the user.

McAfee researcher Yichong Lin explained that the vulnerability was first disclosed in a Chinese security publication known as Pstzine.

Lin noted that a similar concept, known as Ghost Pages, has previously been discussed by researchers.

While there is no currently available fix for the vulnerability, Firefox and Internet Explorer 7 are protected from the attack.

McAfee and US-Cert recommend that IE6 users upgrade to the latest version of the browser to avoid infection. Users who do not wish to upgrade are advised to disable scripting.

Copyright © 2008 vnunet.com

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Vulnerabilities & Exploits Whitepapers