PT-2008-5998 · Microsoft · Internet Explorer
Published
2008-10-29
·
Updated
2018-10-11
·
CVE-2008-4788
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer version 6
Description
The issue allows remote attackers to spoof the address bar by omitting high-bit URL-encoded characters when displaying the address bar. This can be achieved via a URL with a domain name that differs from an important domain name only in these characters. For example, using
exam%A9ple.com to spoof example.com.Recommendations
For Microsoft Internet Explorer version 6, consider updating to a newer version to mitigate the risk of address bar spoofing. As a temporary workaround, users should be cautious when clicking on links from untrusted sources and verify the authenticity of websites by checking the URL in the address bar.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer