SecurityFocus: Using the back button in IE is dangerous. [via Slashdot: Don't Hit That Back Button] IE allows urls containing the javascript protocoll in the history list.
Code injected in the url will operate in the same zone/domain as the last
url viewed. The javascript url can be set to trigger when a user presses
the backbutton.

