Cross-Site Scripting Vulnerability in Microsoft Internet Explorer with Wildcard DNS Entry
Microsoft Internet Explorer is reported to contain a cross-site scripting vulnerability for sites that have a wildcard DNS entry. A web server with a wildcard DNS entry will respond to any hostname requested. Internet Explorer improperly interprets text inside of an anchor tag as HTML, rather than plaintext. An attacker can exploit this vulnerability by finding or creating a web site using a wildcard DNS entry and configuring it to display the hostname received in the request in the HTML returned to the user. This allows the attacker to potentially execute HTML or script code in the security context of the vulnerable site, leading to theft of cookie authentication credentials or other types of attacks.