Multiple Web Browsers contain a flaw that may allow a malicious user to spoof the content of websites. The issue is triggered when arbitrary content is loaded from a malicious website in an separate frame in another browser window. It is possible that this flaw may allow content to load that appears to originate from a trusted site, resulting in a loss of integrity.
Classification
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
Technical
While this vulnerability dates back to 1998, many web browsers since then have been coded with this issue. In other cases, some web browsers such as Firefox and Mozilla have fixed the vulnerability and then re-introduced it in later versions.
Solution
Depending upon the vendor, either upgrade to the most recent release or install the available patches, as these solutions have been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround(s): do not visit or follow links from untrusted websites.