# New Windows/IE Bug

**URL:** <https://forum.kirupa.com/t/new-windows-ie-bug/106836>\
**Category:** Uncategorized\
**Created:** [April 9, 2004, 9:58am UTC](https://forum.kirupa.com/t/new-windows-ie-bug/106836 "2004-04-09T09:58:27Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![955](https://avatars.discourse-cdn.com/v4/letter/9/4bbf92/32.png) [@955](https://forum.kirupa.com/u/955)\
**Post date:** [April 9, 2004, 9:58am UTC](https://forum.kirupa.com/t/new-windows-ie-bug/106836/1 "2004-04-09T09:58:27Z")

</div>

[http://www.us-cert.gov/cas/techalerts/TA04-099A](http://www.us-cert.gov/cas/techalerts/TA04-099A).

A cross-domain scripting vulnerability in Microsoft Internet Explorer (IE) could allow an attacker to execute arbitrary code with the privileges of the user running IE. The attacker could also read and manipulate data on web sites in other domains or zones.

There’s a demo here: [http://ip3e83566f.speed.planet.nl/security/newone/exploit.htm](http://ip3e83566f.speed.planet.nl/security/newone/exploit.htm)

If you use windows media player, back up C:/Program Files/Windows Media Player/wmplayer.exe before running the demo 😉
