|
|
|
Vulnerability Note VU#347188Microsoft Internet Explorer 7 may allow address bar spoofingOverviewInternet Explorer 7 may allow address bar spoofing in pop-up windows. This could let an attacker spoof the address of a web site.I. DescriptionInternet Explorer 7 includes a new feature called "Address bar protection." This makes sure that every window, including pop-ups, will present an address bar to the user. By using a specially crafted URI, an attacker can spoof this address bar in a pop-up window.II. ImpactThis vulnerability could be used to convince a user that the intruder's web site was actually a web site that the user trusts and might provide sensitive information to.III. SolutionWe are currently unaware of a practical solution to this problem.Disable Active scripting
Referenceshttp://www.us-cert.gov/reading_room/securing_browser/#Internet_Explorer This vulnerability was publicly disclosed by Secunia. This document was written by Will Dormann.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||