Secunia, a Danish security research outfit, confirmed postings to the Full-Disclosure mailing list that said IE can be tricked into displaying content of an attacker’s choice in a frame of a third-party site, as long as they know the name of the frame.

This could be used, for example, to inject malware into a page so that it looks like it is coming from a trusted source. The vulnerability is similar to one fixed in IE 3 and 4 in 1998, according to Secunia.