Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy and inject arbitrary web script or HTML via vectors involving an IFRAME element that triggers a redirect, a second IFRAME element that does not trigger a redirect, and an eval of a WindowProxy object, aka "Universal XSS (UXSS)."
https://exchange.xforce.ibmcloud.com/vulnerabilities/100606
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-018
http://www.securitytracker.com/id/1031888
http://www.securityfocus.com/bid/72489
http://www.securityfocus.com/archive/1/534662/100/0/threaded
http://secunia.com/advisories/62658