NewsIE Climbs Into the "It's Not a Bug, It's a Feature" Browser Doghouse with Unpatched GIF Vulnerability
Posted 07/01/08 at 03:08:34 PM by Mark Edward Soper

According to Kapersky Labs analyst Roel Schouwenberg, GIF files can include embedded JavaScript, and under certain circumstances, can be used to launch a cross-site-scripting (XSS) attack. Internet Explorer's vulnerable to this threat, and at least one web site's already been affected.
To find out how long Redmond's known about this problem, and how another browser vendor set Microsoft an example in how to deal with a reported vulnerability, join us after the jump.
RESOURCE CENTER
THIS MONTH's ISSUE





