Cross-Site History Manipulation (XSHM)

2010-02-01 Thread Alex Roichman
Checkmarx Research Labs has identified a new critical vulnerability in Internet Explorer (other browsers are probably exposed the same way) that would allow hackers to easily compromise web applications. Cross-Site History Manipulation (XSHM) is a newly discovered zero-day attack: attackers may

Re: Cross-Site History Manipulation (XSHM)

2010-02-01 Thread Michal Zalewski
From the post: Checkmarx Research Labs has identified a new critical vulnerability in Internet Explorer (other browsers are probably exposed the same way) that would allow hackers to easily compromise web applications. I'm sorry if this response sounds harsh, but phrases such as critical