Microsoft Internet Explorer NavCancel.HTM Cross-Site Scripting Vulnerability
BID:22966
Info
Microsoft Internet Explorer NavCancel.HTM Cross-Site Scripting Vulnerability
| Bugtraq ID: | 22966 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-1499 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 14 2007 12:00AM |
| Updated: | Jun 21 2007 10:39PM |
| Credit: | Aviv Raff is credited with the discovery of this issue. |
| Vulnerable: |
Nortel Networks Centrex IP Client Manager 8.0 Nortel Networks Centrex IP Client Manager 7.0 Nortel Networks Centrex IP Client Manager 9.0 Nortel Networks Centrex IP Client Manager Microsoft Internet Explorer 7.0 HP Storage Management Appliance 2.1 HP Storage Management Appliance 2.1 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server 0 Avaya CIE 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer NavCancel.HTM Cross-Site Scripting Vulnerability
Microsoft Internet Explorer is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied data.
An attacker can exploit this issue to spoof the contents of the Navigation canceled page, steal cookie-based authentication credentials, and obtain other sensitive information. Successful exploits may assist in phishing or other attacks that rely on content spoofing.
Microsoft Internet Explorer is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied data.
An attacker can exploit this issue to spoof the contents of the Navigation canceled page, steal cookie-based authentication credentials, and obtain other sensitive information. Successful exploits may assist in phishing or other attacks that rely on content spoofing.
Exploit / POC
Microsoft Internet Explorer NavCancel.HTM Cross-Site Scripting Vulnerability
To exploit this issue, an attacker must entice a victim to follow a maliciously crafted URI.
The following proof-of-concept URI is available:
res://ieframe.dll/navcancl.htm#http://www.example.com/[script]
To exploit this issue, an attacker must entice a victim to follow a maliciously crafted URI.
The following proof-of-concept URI is available:
res://ieframe.dll/navcancl.htm#http://www.example.com/[script]
Solution / Fix
Microsoft Internet Explorer NavCancel.HTM Cross-Site Scripting Vulnerability
Solution:
The vendor released an advisory and fixes to address this issue. Please see the references for more information.
Microsoft Internet Explorer 7.0
Solution:
The vendor released an advisory and fixes to address this issue. Please see the references for more information.
Microsoft Internet Explorer 7.0
-
Microsoft Cumulative Update for Internet Explorer 7 for Windows Server 2003 (KB933566)
http://www.microsoft.com/downloads/details.aspx?FamilyId=A074D9C0-1FED -4753-845E-073CFCE99F45 -
Microsoft Cumulative Update for Internet Explorer 7 for Windows Server 2003 64-bit Itanium Edition (KB933566)
http://www.microsoft.com/downloads/details.aspx?FamilyId=77287386-48EB -4AA9-9537-626A3093AAF7&displaylang=en -
Microsoft Cumulative Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB933566)
http://www.microsoft.com/downloads/details.aspx?FamilyId=69C526B8-8B07 -42BC-9BED-E18DEAE21C8E -
Microsoft Cumulative Update for Internet Explorer 7 for Windows XP Service Pack 2 (KB933566)
http://www.microsoft.com/downloads/details.aspx?FamilyId=C2191703-8CBD -4959-9F84-E13F21173926 -
Microsoft Cumulative Update for Internet Explorer 7 in Windows Vista x64 Edition (KB933566)
http://www.microsoft.com/downloads/details.aspx?FamilyId=77287386-48EB -4AA9-9537-626A3093AAF7 -
Microsoft Cumulative Update for Internet Explorer 7 for Windows XP x64 Edition (KB933566)
http://www.microsoft.com/downloads/details.aspx?FamilyId=69C526B8-8B07 -42BC-9BED-E18DEAE21C8E
References
Microsoft Internet Explorer NavCancel.HTM Cross-Site Scripting Vulnerability
References:
References:
- Microsoft Internet Explorer Homepage (Microsoft)
- Phishing using IE7 local resource vulnerability (Aviv Raff On .NET)
- [SECURITY ADVISORY ] Centrex IP Client Manager (CICM) response to Microsoft June (Nortel Networks)
- ASA-2007-258 MS07-033 Cumulative Security Update for Internet Explorer (933566) (Avaya)
- Microsoft Security Bulletin MS07-033 (Microsoft)