Taken from: http://www.zapthedingbat.com/security/ex01/vun1.htm, reproduced here for posterity and link longevity.
Vulnerability
There is a flaw in the way that Internet Explorer displays URLs in the address bar.
By opening a specially crafted URL an attacker can open a page that appears to be from a different domain from the current location.
Exploit
By opening a window using the http://user@domain nomenclature an attacker can hide the real location of the page by including a non printing character (%01) before the "@".
Internet Explorer doesn't display the rest of the URL making the page appear to be at a different domain.