“If the attacker can figure out a flaw in the way IE 8 is actually doing that output encoding and then create a specific string the attacker will know will be transformed into an actual attack, they could use that to input a value … that actually results in an attack firing on the page. This could be a way to introduce an attack into a page that didn’t have a vulnerability otherwise,” said Michael Coates of Aspect Security.
Source: The Register

Articles
Blogs
Kits
Forums
