IE 6
. A remote user can create malicious HTML that includes the popup object tag to cause an existing program on another user's host to be executed when the other user (the victim) loads the HTML.
A remote user can create HTML that will cause an application on the other user's host to be executed without authorization.
While no solution was available from Microsoft at this time, disabling active scripting is a suggested workaround.
reported by: the Pull