FYI…

IE - drag and drop vuln
- http://www.kb.cert.org/vuls/id/526089
"…Impact
By convincing a user to perform a drag and drop operation, an attacker could copy malicious code to the local file system…
Last Updated 09/16/2004 …"

- http://secunia.com/advisories/12321/
"… The vulnerability is actively being exploited in the wild…"

.