|
Microsoft Internet Explorer contains a flaw in the cross-origin policy. The issue is triggered by a crafted HTML document containing a resource served with the content-disposition: attachment header. The resulting download can be from a third-party web site that will appear to come from a legitimate server. This may allow an attacker to force navigation towards a malicious download containing malware.
|