New flaws have been found in the newest version of Microsoft Internet Explorer for Windows and Mozilla Firefox for Windows and Unix.
The way it works is that an unsuspecting web visitor surfs a webpage where he or she has to enter certain characters on a field. Once entered, the user’s sensitive hardrive contents will be revealed to an attacker.
This method involves the features in Windows and Unix that lets a user upload a file to a remote server using either the Internet Explorer or Firefox programs.
Microsoft is currently investigating the situation.
Source: The Register

Articles
Blogs
Kits
Forums