Antivirus Advice for Computer Protection on the Internet




Microsoft Internet Explorer 6 Cross-Domain Vulnerability

US-CERT is aware of publicly available proof-of-concept code for a new vulnerability in Microsoft Internet Explorer 6. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary script in the context of another domain. This could allow an attacker to take a variety of actions, including stealing cookies, hijacking a web session, or stealing authentication credentials. At this time, Internet Explorer 7 does not appear to be affected by this issue.

US-CERT  strongly encourages users to upgrade to Microsoft Internet Explorer 7 and follow the best security practices as outlined in the Securing Your Web Browser document to help mitigate the risk. Additional information about this vulnerability can be found in the Vulnerability Notes Database.

US-CERT will provide additional information as it becomes available.

Read more: US-CERT Current Activity

 







Today's Internet Security Alerts


Popular Words in Security Alerts
server android backup maintain prevent realplayer attempts addresses campaign authentication receiving protocol internet peoplesoft infection