CVE-2007-3092
Microsoft Internet Explorer 6 allows remote attackers to spoof the URL bar, and page properties including SSL certificates, by interrupting page loading through certain use of location DOM objects and setTimeout calls.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 20.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Internet Explorer 6 allows remote attackers to spoof the URL bar, and page properties including SSL certificates, by interrupting page loading through certain use of location DOM objects and setTimeout calls. NOTE: this issue can be leveraged for phishing and other attacks.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 19.98% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/internet explorer
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2007-06/0026.htmlBroken Link
- http://lcamtuf.coredump.cx/ietrap2/Broken Link
- http://osvdb.org/45437Broken Link
- http://secunia.com/advisories/25564Not Applicable
- http://securityreason.com/securityalert/2781Exploit, Third Party Advisory
- http://securitytracker.com/id?1018193Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/470446/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/24298Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34705VDB Entry
- http://archives.neohapsis.com/archives/fulldisclosure/2007-06/0026.htmlBroken Link
- http://lcamtuf.coredump.cx/ietrap2/Broken Link
- http://osvdb.org/45437Broken Link
- http://secunia.com/advisories/25564Not Applicable
- http://securityreason.com/securityalert/2781Exploit, Third Party Advisory
- http://securitytracker.com/id?1018193Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/470446/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/24298Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34705VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.