Microsoft Internet Explorer User Security Confirmation Bypass Vulnerability
BID:11200
Info
Microsoft Internet Explorer User Security Confirmation Bypass Vulnerability
| Bugtraq ID: | 11200 |
| Class: | Design Error |
| CVE: |
CVE-2004-1686 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 16 2004 12:00AM |
| Updated: | Jan 04 2007 06:27PM |
| Credit: | Disclosure of this issue is credited to Cyrille SZYMANSKI. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP2 - do not use |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer User Security Confirmation Bypass Vulnerability
Reportedly, Microsoft Internet Explorer is affected by a vulnerability that allows users to bypass security confirmation. This issue is due to a design error that allows malicious users to trivially bypass the requirement for user confirmation.
An attacker may leverage this issue by hosting a web page or pages designed to bypass the required user confirmation; this would facilitate the execution of arbitrary client-side scripts such as JavaScript and ActiveX objects in the browsers of unsuspecting users that visit the site.
Reportedly, Microsoft Internet Explorer is affected by a vulnerability that allows users to bypass security confirmation. This issue is due to a design error that allows malicious users to trivially bypass the requirement for user confirmation.
An attacker may leverage this issue by hosting a web page or pages designed to bypass the required user confirmation; this would facilitate the execution of arbitrary client-side scripts such as JavaScript and ActiveX objects in the browsers of unsuspecting users that visit the site.
Exploit / POC
Microsoft Internet Explorer User Security Confirmation Bypass Vulnerability
No exploit is required to leverage this issue. Reportedly, a comment of the following form when placed between the '<!DOCTYPE>' and '<HTML>' tags will trigger this issue:
<!-- saved from usr=(XXXX)URL -->
where 'URL' is a URL string such as 'http://www.example.com' and 'XXXX' is a four-digit number that corresponds to the number of characters in the URL string.
No exploit is required to leverage this issue. Reportedly, a comment of the following form when placed between the '<!DOCTYPE>' and '<HTML>' tags will trigger this issue:
<!-- saved from usr=(XXXX)URL -->
where 'URL' is a URL string such as 'http://www.example.com' and 'XXXX' is a four-digit number that corresponds to the number of characters in the URL string.
Solution / Fix
Microsoft Internet Explorer User Security Confirmation Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Microsoft Internet Explorer User Security Confirmation Bypass Vulnerability
References:
References:
- IE6 + XP SP2 Vulnerability (cns
)