Microsoft Internet Explorer ' ' Address Bar URI Spoofing Vulnerability
BID:31960
Info
Microsoft Internet Explorer ' ' Address Bar URI Spoofing Vulnerability
| Bugtraq ID: | 31960 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4787 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 27 2008 12:00AM |
| Updated: | May 07 2015 05:22PM |
| Credit: | Amit Klein |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer ' ' Address Bar URI Spoofing Vulnerability
Internet Explorer is affected by a URI-spoofing vulnerability because it fails to adequately handle specific combinations of the non-breaking space character (' ').
An attacker may leverage this issue to spoof the source URI of a site presented to an unsuspecting user. This may lead to a false sense of trust because the user may be presented with a source URI of a trusted site while interacting with the attacker's malicious site.
Internet Explorer 6 is affected by this issue.
Internet Explorer is affected by a URI-spoofing vulnerability because it fails to adequately handle specific combinations of the non-breaking space character (' ').
An attacker may leverage this issue to spoof the source URI of a site presented to an unsuspecting user. This may lead to a false sense of trust because the user may be presented with a source URI of a trusted site while interacting with the attacker's malicious site.
Internet Explorer 6 is affected by this issue.
Exploit / POC
Microsoft Internet Explorer ' ' Address Bar URI Spoofing Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web document.
The following example exploit is available:
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web document.
The following example exploit is available:
Solution / Fix
Microsoft Internet Explorer ' ' Address Bar URI Spoofing Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Internet Explorer ' ' Address Bar URI Spoofing Vulnerability
References:
References:
- Microsoft Internet Explorer Homepage (Microsoft)
- Writeup by Amit Klein (Trusteer): Address Bar Spoofing for IE6 (Amit Klein
)