Original URL: https://www.theregister.com/2002/09/10/ie_6_sp1_omits_fixes/

IE 6 SP1 omits fixes for 20 outstanding flaws

In the frame

By John Leyden

Posted in Security, 10th September 2002 16:56 GMT

Researchers have discovered that inadequate security restrictions in Internet Explorer make it possible for an attacker to execute script on any Web page that containing frames.

Grey Magic Software describes the vulnerability as critical, a warning backed up by several proof of concept demonstrations.

Because of the way frames (and iframes) are handled by IE version 5.5 and above, attackers are able to get to all sorts of mischief with minimal effort, including:

Users of Internet Explorer 5.5 and above are vulnerable to these various exploits with IE 6.0 users particularly vulnerable.



Fortunately there is a simple workaround available which involves disabling Active Scripting. Well either that or consider moving to an alternative browser.

GreyMagic published its advisory yesterday after discovering the flaw in August 4. Still no word from Microsoft on the issue, a fix for this particular problem doesn't appear in a list of fixes included in Microsoft's release of Service Pack 1 for IE6, which was released today. ®

Related Stories

MS IE patch misses the mark
IE, Outlook run malicious commands without scripting
Dangers of the Google tool bar exposed
Ditch IE - veteran bug hunter