PT-2004-1203 · Microsoft · Internet Explorer
Zap The Dingbat
·
Published
2004-01-06
·
Updated
2021-07-23
·
CVE-2003-1025
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Internet Explorer versions 5.01 through 6 SP1
Description
The issue allows remote attackers to spoof the domain of a URL by using a "%01" character before an @ sign in the
user@domain portion of the URL. This hides the rest of the URL, including the real site, in the address bar.Recommendations
For Internet Explorer versions 5.01 through 6 SP1, consider avoiding the use of URLs with the "%01" character before an @ sign in the user@domain portion until a fix is available. As a temporary workaround, carefully verify the URL in the address bar to ensure it matches the expected domain.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer