Description: A vulnerability has been reported in Internet Explorer, which can be exploited by malicious people to trick users into disclosing sensitive information.
The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 or 7 on Microsoft Windows XP SP2. Other versions may also be affected.
Solution: Disable Active Scripting support.
Do not enter suspicious text when visiting untrusted web sites.
Provided and/or discovered by: Additional Information:
Michal Zalewski
Changelog: 2007-02-12: Added additional information that includes latest affected version based on research by Michal Zalewski.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.