Microsoft Internet Explorer contains a flaw that allows a remote cross site scripting attack. This flaw exists due to the way a browser handles character sets when none is defined by the initial webpage. This could allow a malicious user to create a specially crafted iframe that would execute arbitrary code in the user's browser, leading to a loss of integrity.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Unknown
Solution
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.
This story is wrtten by hasegawa.yosuke in webappsec.jp(Japanese only blog) ... occur XSS by combining with CVE-2007-1114 if Web Application send these character encoding name