The problem lies in the way Microsoft has implemented a JavaScript
component in its Web browser, security researcher Amit Klein wrote in a
research document. Internet Explorer does not validate some data fields
provided by a PC when the component, called XmlHttpRequest, is used, he
wrote.
This affects IE 6 (even with Window XP SP2). It can be thwarted by setting the security to “High.”
This just another example of how bad IE is and how vulnerable our
browser can be. Once again I recommend switching to Firefox.
Lets hope and pray that IE 7 is not as flawed as all previous versions of Internet Explorer.
read more | digg story
Ready to actually get the RMF/ISSO job?
Go from reading about the Risk Management Framework to doing it — with the full video course, the books, and a community of GRC professionals taught by Bruce Brown (CISSP, CGRC).
Get the RMF ISSO Foundations course → Browse the RMF & GRC books Join the free GRC community
Leave a Reply