VU#251788 - Microsoft Internet Explorer does not safely handle multiple file download requests
06/04/2003
When Internet Explorer (IE) parses an HTML document containing a frame (FRAME or IFRAME element) that specifies an executable file (.exe) as its source, a dialog window is displayed that asks the user how to handle the file. The dialog window prompts the user to execute the file, save the file, or cancel the operation. When handling a document that contains a sufficiently large number of such frame elements, IE fails to apply the expected security restrictions to the frame and executes the specified file without user intervention. Other software that uses the WebBrowser ActiveX control may be affected.
http://www.kb.cert.org/vuls/id/251788
questo vuol dire che se un frameset contiene molti frames o iframe, che a loro volta hanno all'interno dei file exe, exploder si dimentica di fare il controllo sulla sicurezza, e esegue allegramente i file.
www.mozilla.org/projects/firebird ad esempio no...