PT-2004-1203 · Microsoft · Internet Explorer

Zap The Dingbat

·

Publicado

2004-01-06

·

Atualizado

2021-07-23

·

CVE-2003-1025

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Internet Explorer versions 5.01 through 6 SP1
Description The issue allows remote attackers to spoof the domain of a URL by using a "%01" character before an @ sign in the user@domain portion of the URL. This hides the rest of the URL, including the real site, in the address bar.
Recommendations For Internet Explorer versions 5.01 through 6 SP1, consider avoiding the use of URLs with the "%01" character before an @ sign in the user@domain portion until a fix is available. As a temporary workaround, carefully verify the URL in the address bar to ensure it matches the expected domain.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2003-1025

Produtos afetados

Internet Explorer