Page is a not externally linkable
- Code, Content, and Presentation
-- HTML
---- IE Vulnerability: Address Bar Spoofing


pageoneresults - 7:14 pm on Apr 17, 2006 (gmt 0)


2006-04-04 - Internet Explorer Window Loading Race Condition Address Bar Spoofing
[secunia.com...]

Please note, there is no fix for this vulnerability from MS as of yet. Secunia advises to Disable Active Scripting support.

Description:
Hai Nam Luke has discovered a vulnerability in Internet Explorer, which can be exploited by malicious people to conduct phishing attacks.

The vulnerability is caused due to a race condition in the loading of web content and Macromedia Flash Format files (".swf") in browser windows. This can be exploited to spoof the address bar in a browser window showing web content from a malicious web site.

Secunia has constructed a test, which can be used to check if your browser is affected by this issue:

[secunia.com...]

The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP1/SP2. The vulnerability has also been confirmed in Internet Explorer 7 Beta 2 Preview (March edition). Other versions may also be affected.


Thread source:: http://www.webmasterworld.com/html/12101.htm
Brought to you by WebmasterWorld: http://www.webmasterworld.com