Definition
New Search
Microsoft Internet Explorer 6 through 8 spoofing vulnerability
oval:org.mitre.oval:def:12817
Microsoft Internet Explorer 6 through 8 allows remote attackers to spoof the address bar via window.open with a relative URI to show an arbitrary URL on the web site visited by the victim as demonstrated by a visit to an attacker-controlled web page which triggers a spoofed login form for the site containing that page.
Family:
windows
Status:
ACCEPTED
Platform(s):
- Microsoft Windows Server 2008
- Microsoft Windows Vista
- Microsoft Windows 2000
- Microsoft Windows 7
- Microsoft Windows Server 2003
- Microsoft Windows XP
Class:
vulnerability
Reference(s):
- CVE-2009-3003
Product(s):
- Microsoft Internet Explorer 6
- Microsoft Internet Explorer 8
- Microsoft Internet Explorer 7