Forum Moderators: open

Message Too Old, No Replies

Internet Explorer DHTML Edit ActiveX Control Cross-Site Scripting

Secunia Advisory: SA13482 Release Date: 2004-12-16

         

pendanticist

12:20 am on Dec 18, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



[secunia.com...]

The vulnerability is caused due to an error in the DHTML Edit ActiveX control when handling the "execScript()" function in certain situations. This can be exploited to execute arbitrary script code in a user's browser session in context of an arbitrary site.

tedster

6:26 pm on Dec 18, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



On that same page - a note about a PDF vulnerability that can be fixed with an update.