PT-2009-5343 · Microsoft · Internet Explorer

Lostmon

·

Published

2009-08-28

·

Updated

2017-09-19

·

CVE-2009-3003

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Microsoft Internet Explorer versions 6 through 8
Description: The issue allows remote attackers to spoof the address bar. This can be achieved via window.open with a relative URI, showing an arbitrary URL on the web site visited by the victim. For example, a visit to an attacker-controlled web page can trigger a spoofed login form for the site containing that page.
Recommendations: For Microsoft Internet Explorer versions 6 through 8, consider avoiding the use of window.open with relative URIs until a fix is available. As a temporary workaround, restrict access to potentially malicious web pages to minimize the risk of address bar spoofing.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-3003

Affected Products

Internet Explorer