newsbot
20-12-2007, 10:43 PM
This vulnerability allows remote attackers to run arbitrary JavaScript code in the security context of other domains, resulting in information disclosure and session hijacking. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
http://www.securiteam.com/securitynews/6E00L00KKC.html
http://www.securiteam.com/securitynews/6E00L00KKC.html