PT-2004-1203 · Microsoft · Internet Explorer
Zap The Dingbat
·
Publicado
2004-01-06
·
Atualizado
2021-07-23
·
CVE-2003-1025
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Internet Explorer versions 5.01 through 6 SP1
Description
The issue allows remote attackers to spoof the domain of a URL by using a "%01" character before an @ sign in the
user@domain portion of the URL. This hides the rest of the URL, including the real site, in the address bar.Recommendations
For Internet Explorer versions 5.01 through 6 SP1, consider avoiding the use of URLs with the "%01" character before an @ sign in the user@domain portion until a fix is available. As a temporary workaround, carefully verify the URL in the address bar to ensure it matches the expected domain.
Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Internet Explorer