The bug, which opens the door to URL spoofing attacks, was found on a fully patched system running IE 6.0 and Windows XP Service Pack 2.
Read more
Read more