Microsoft Internet Explorer Pop-up Window Title Bar Spoofing Weakness
BID:12602
Info
Microsoft Internet Explorer Pop-up Window Title Bar Spoofing Weakness
| Bugtraq ID: | 12602 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2005 12:00AM |
| Updated: | Feb 21 2005 12:00AM |
| Credit: | Discovery of this weakness is credited to bitlance winter <bitlance_3hotmail.com>. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP2 - do not use Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer Pop-up Window Title Bar Spoofing Weakness
Internet Explorer is reported prone to a pop-up window title bar spoofing weakness.
The weakness is reported to exist due to a flaw that manifests in script-initiated pop-up windows.
This issue may be leveraged by an attacker to display false URI information in the title bar of an Internet Explorer pop-up dialog window. This may facilitate phishing style attacks; other attacks may also be possible.
Internet Explorer is reported prone to a pop-up window title bar spoofing weakness.
The weakness is reported to exist due to a flaw that manifests in script-initiated pop-up windows.
This issue may be leveraged by an attacker to display false URI information in the title bar of an Internet Explorer pop-up dialog window. This may facilitate phishing style attacks; other attacks may also be possible.
Exploit / POC
Microsoft Internet Explorer Pop-up Window Title Bar Spoofing Weakness
The following exploit is available:
The following exploit is available:
Solution / Fix
Microsoft Internet Explorer Pop-up Window Title Bar Spoofing Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Internet Explorer Pop-up Window Title Bar Spoofing Weakness
References:
References:
- Technet Security (Microsoft)