Microsoft Internet Explorer 7 Popup Window Address Bar URI Spoofing Vulnerability
BID:28498
Info
Microsoft Internet Explorer 7 Popup Window Address Bar URI Spoofing Vulnerability
| Bugtraq ID: | 28498 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 28 2008 12:00AM |
| Updated: | Mar 31 2008 04:09PM |
| Credit: | Juan Pablo Lopez Yacubian |
| Vulnerable: |
Microsoft Internet Explorer 7.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer 7 Popup Window Address Bar URI Spoofing Vulnerability
Internet Explorer 7 is affected by a URI-spoofing vulnerability.
An attacker may leverage this issue by inserting strings to spoof the source URI of a file presented to an unsuspecting user. This may lead to a false sense of trust because the user may be presented with a source URI of a trusted site while interacting with the attacker's malicious site.
Internet Explorer 7 is affected by this issue.
Reports indicate that unspecified versions of Firefox are also prone to this issue, but this has not been confirmed.
Internet Explorer 7 is affected by a URI-spoofing vulnerability.
An attacker may leverage this issue by inserting strings to spoof the source URI of a file presented to an unsuspecting user. This may lead to a false sense of trust because the user may be presented with a source URI of a trusted site while interacting with the attacker's malicious site.
Internet Explorer 7 is affected by this issue.
Reports indicate that unspecified versions of Firefox are also prone to this issue, but this has not been confirmed.
Exploit / POC
Microsoft Internet Explorer 7 Popup Window Address Bar URI Spoofing Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web document.
The following example exploit is available:
http://es.geocities.com/jplopezy/iespoof.html
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web document.
The following example exploit is available:
http://es.geocities.com/jplopezy/iespoof.html
Solution / Fix
Microsoft Internet Explorer 7 Popup Window Address Bar URI Spoofing Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Internet Explorer 7 Popup Window Address Bar URI Spoofing Vulnerability
References:
References: