Microsoft Internet Explorer Spoofed Address Bar Vulnerability
BID:10943
Info
Microsoft Internet Explorer Spoofed Address Bar Vulnerability
| Bugtraq ID: | 10943 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 16 2004 12:00AM |
| Updated: | Aug 16 2004 12:00AM |
| Credit: | Discovery is credited to Liu Die Yu. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer Spoofed Address Bar Vulnerability
Microsoft Internet Explorer may allow a malicious Web page to spoof the address bar of the browser. This could be used to lure Web users into a false sense of trust since a malicious or spoofed site may pose as a site that is trusted by the user. This could facilitate phishing attacks.
It may also be possible to exploit this issue through HTML email.
Microsoft Internet Explorer may allow a malicious Web page to spoof the address bar of the browser. This could be used to lure Web users into a false sense of trust since a malicious or spoofed site may pose as a site that is trusted by the user. This could facilitate phishing attacks.
It may also be possible to exploit this issue through HTML email.
Exploit / POC
Microsoft Internet Explorer Spoofed Address Bar Vulnerability
A proof-of-concept was published at the following location:
http://umbrella.name/originalvuln/msie/NullyFake/test.htm
A proof-of-concept was published at the following location:
http://umbrella.name/originalvuln/msie/NullyFake/test.htm
Solution / Fix
Microsoft Internet Explorer Spoofed Address Bar Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.