[37273] in bugtraq
Re: [Full-Disclosure] MSIE
daemon@ATHENA.MIT.EDU (Menashe Eliezer)
Tue Nov 9 02:38:58 2004
Date: 8 Nov 2004 04:34:00 -0000
Message-ID: <20041108043400.30541.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: Menashe Eliezer <menashe@finjan.com>
To: bugtraq@securityfocus.com
In-Reply-To: <BAY10-DAV29UqLpHkat00000751@hotmail.com>
The published exploit is working also with the <EMBED> tag, and not just with the <IFRAME> and the <FRAME> tags.
Finjan's advisory can be found at: http://www.finjan.com/SecurityLab/AttackandExploitReports/alert_show.asp?attack_release_id=114
==
Regards,
Menashe Eliezer
Senior application security architect
Malicious Code Research Center
Finjan Software
http://www.finjan.com/mcrc
Prevention is the best cure!