- Frame injection
"For other uses of the term "frame injection", see
Frame injection (disambiguation) ."A frame injection attack is an attack on
Internet Explorer 5 ,Internet Explorer 6 andInternet Explorer 7 to load arbitrary code in the browser. [cite web|url=http://secunia.com/advisories/11966/ |title=Internet Explorer Frame Injection Vulnerability |work= Vulnerability Intelligence |publisher=Secunia Advisories |date= |accessdate=2008-09-13] This attack is causedInternet Explorer not checking the destination of the resulting frame, [cite web|url=http://www.microsoft.com/technet/security/bulletin/ms98-020.mspx |title=Microsoft Security Bulletin (MS98-020) |publisher=Microsoft Corporation |date= |accessdate=2008-09-13] therefore allowing arbitrary code such asJavascript orVBScript . This also happens when code gets injected through frames due to scripts not validating their input. [cite web|url=http://www.owasp.org/index.php/Cross_Frame_Scripting |title=Cross Frame Scripting - OWASP |publisher=OWASP |date= |accessdate=2008-09-13] This other type of frame injection affects all browsers and scripts that do not validate untrusted input. [cite web|url=http://secunia.com/cve_reference/CVE-2004-0719/ |archiveurl=http://web.archive.org/web/20071219181848/http://secunia.com/cve_reference/CVE-2004-0719/ |archivedate=2007-12-19 |title=Secunia Advisory|publisher=Secunia |date= |accessdate=2008-09-13]References
External links
* [http://secunia.com/advisories/11966/ Secunia advisory]
* [http://www.microsoft.com/technet/security/bulletin/ms98-020.mspx Microsoft security bulletin]
Wikimedia Foundation. 2010.