2006-03-28

doc_strange: (Default)
2006-03-28 01:05 pm

Serious unpatched issue in Internet Explorer

There is a very serious, unpatched issue with IE right now. In short, IE will happily treat an html (or, apparently, text!) file containing Active Scripting elements as a safe document. Hilarity ensues.

You can:
1) turn off Active Scripting, or
2) stop using IE (recommended!), or
3) Use the workaround patch from eEye

If you use the patch, remember to uninstall it before installing the official MS patch (when it comes out). eEye has made that part easy, by the way.

I prefer option #2.