If successfully executed, US-Cert believes that an attacker could execute a cross-domain scripting attack in which the attacker could steal such things as cookies and security credentials without any warning to the user.
According to McAfee researcher Yichong Lin, the vulnerability was first disclosed in a Chinese security publication known as 'pstzine.' Lin noted that a similar concept, known as "Ghost Pages" has previously been discussed by researchers.
While there is no fix for the vulnerability currently available, both Firefox and Internet Explorer 7 are protected from the attack. Both McAfee and US-Cert recommend that IE 6 users upgrade to the latest version of the browser to avoid infection.
Users who do not wish to upgrade are advised by both companies to disable scripting.