AplusWebMaster
Topic Starter
FYI…
- http://secunia.com/advisories/19521/
Release Date: 2006-04-04
Critical: Less critical
Impact: Spoofing
Where: From remote
Solution Status: Unpatched
Software: Microsoft Internet Explorer 6.x
Description:
…The vulnerability is caused due to a race condition in the loading of web content and Macromedia Flash Format files (".swf") in browser windows. This can be exploited to spoof the address bar in a browser window showing a Flash file from a malicious web site.
NOTE: The impact of exploitation is reduced because the URL of the malicious Flash file is visible in the title of the browser window.
The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP1/SP2. Other versions may also be affected.
Solution:
Disable Active Scripting support…"

- http://secunia.com/advisories/19521/
Release Date: 2006-04-04
Critical: Less critical
Impact: Spoofing
Where: From remote
Solution Status: Unpatched
Software: Microsoft Internet Explorer 6.x
Description:
…The vulnerability is caused due to a race condition in the loading of web content and Macromedia Flash Format files (".swf") in browser windows. This can be exploited to spoof the address bar in a browser window showing a Flash file from a malicious web site.
NOTE: The impact of exploitation is reduced because the URL of the malicious Flash file is visible in the title of the browser window.
The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP1/SP2. Other versions may also be affected.
Solution:
Disable Active Scripting support…"