Resident scripts and global cross-domain
In October of 2006, a vulnerability in IE7 known as the “mhtml:” Redirection Information Disclosure was discovered. RSnake wrote up a post about how nasty it was. The basics: it took over the entire browser experience.
Fortunately, the bug was patched quickly, it required access to the web server/application (or HTTP header injection), and it only [...]
