PT-2003-1128 · Microsoft · Internet Explorer
Published
2003-07-17
·
Updated
2021-07-23
·
CVE-2001-1410
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Internet Explorer versions 6 and earlier
Description
The issue allows remote attackers to create chromeless windows using the Javascript
window.createPopup method. This could enable attackers to simulate a victim's display and conduct unauthorized activities or steal sensitive data via social engineering.Recommendations
For Internet Explorer versions 6 and earlier, consider disabling the
window.createPopup method as a temporary workaround until a patch is available. Restrict access to sensitive data and be cautious of social engineering attempts that may utilize this issue.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer