Microsoft is working on patch, but for now malicious sites could siphon information from IE 5.5 and 6.0.

A newly reported vulnerability in Microsoft’s Internet Explorer allows hackers to steal or corrupt cookie information on a user’s desktop through a malformed URL at a Web site or in an HTML e-mail.

