MS14-010 CVE-2014-0293 Technical Details and Code(I changed the web permanently)

Visit http://technet.microsoft.com/en-us/security/bulletin/ms14-010
Check "Acknowledgments" for "CVE-2014-0293".
It says "Dieyu" and links to my website

Technical Details:
showModalDialog to keep script running, HTTP redirecting to target domain.
Then script will run in target domain.

This is the file that I sent to Microsoft:
SHA1: f50b5aebdc7cd0a62f1ed97d776fe4b7fa47260e
MD5: bfdaa2a329ea639a363a4ba8c294f706




This is exactly the XSS vulnerability that made IE fall in 2004:
"US Government warns against Internet Explorer"
"Vulnerability Note VU#713878", "HTTP Redirection", "showModalDialog"
Microsoft had not fixed it properly for a decade.


Back then, there was no "Local Machine Zone Lockdown", and XSS could get remote code execution.

