Overview
Internet Explorer 7 may allow address bar spoofing in pop-up windows. This could let an attacker spoof the address of a web site.
Description
Internet Explorer 7 includes a new feature called "Address bar protection." This makes sure that every window, including pop-ups, will present an address bar to the user. By using a specially crafted URI, an attacker can spoof this address bar in a pop-up window. |
Impact
This vulnerability could be used to convince a user that the intruder's web site was actually a web site that the user trusts and might provide sensitive information to. |
Solution
We are currently unaware of a practical solution to this problem. |
Disable Active scripting |
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental |
References
Acknowledgements
This vulnerability was publicly disclosed by Secunia.
This document was written by Will Dormann.
Other Information
| CVE IDs: | None |
| Severity Metric: | 2.84 |
| Date Public: | 2006-10-25 |
| Date First Published: | 2006-10-26 |
| Date Last Updated: | 2006-10-26 17:55 UTC |
| Document Revision: | 7 |