Write-up called Hacking with MHTML protocol handler. This discusses cross site scripting via uploading a mhtml file, cross site scripting via mthml-file string injection, bypassing X-Frame-Options, an Adobe Reader cross site scripting issue, and more.
e066afaa1cdd9d529b445023c4567bd6a1940243795411121723e91f3d01bde5