Description: Michal Zalewski has reported two vulnerabilities in Internet Explorer, which potentially can be exploited by a malicious website to display a fake URL in the address bar or to bypass certain security restrictions.
1) A race condition when navigating to a new site from a page can be exploited to perform certain actions and access the contents of the newly loaded page with the permissions of the old page.
2) An error within the handling of "location" DOM objects can be exploited to spoof the URL address bar.
Note: This issue reportedly does not affect Internet Explorer 7.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.