Overview
Internet Explorer 7 may allow address bar spoofing in pop-up windows. This could let an attacker spoof the address of a web site.
Description
Internet Explorer 7 includes a new feature called "Address bar protection." This makes sure that every window, including pop-ups, will present an address bar to the user. By using a specially crafted URI, an attacker can spoof this address bar in a pop-up window. |
Impact
This vulnerability could be used to convince a user that the intruder's web site was actually a web site that the user trusts and might provide sensitive information to. |
Solution
We are currently unaware of a practical solution to this problem. |
Disable Active scripting |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was publicly disclosed by Secunia.
This document was written by Will Dormann.
Other Information
CVE IDs: | None |
Severity Metric: | 2.84 |
Date Public: | 2006-10-25 |
Date First Published: | 2006-10-26 |
Date Last Updated: | 2006-10-26 17:55 UTC |
Document Revision: | 7 |