BleepingComputer.com: New Internet Explorer 7 Spoofing Vulnerability

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

New Internet Explorer 7 Spoofing Vulnerability

#1 User is offline   HIPPO1023 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 84
  • Joined: 19-February 07

Posted 16 March 2007 - 09:51 AM

From : Secunia "Security Watchdog" Blog

Quote

There's a new spoofing vulnerability in Internet Explorer 7, one that could again be exploited by web criminals to perform phishing attacks. This time, the vulnerability is in a local resource file, "navcancl.htm", which is caused by an input validation error when generating a "Refresh the page" link.

...............
...............

The vulnerability remains unpatched, and Microsoft has yet to respond. In the meantime, make sure that you avoid browsing untrusted web sites. In the instance that you encounter the "Refresh the page" link, avoid clicking it. Instead, retype the address bar on your browser, press the browser's Refresh icon, or press F5.

Secunia has created a test that you can take to check if your browser is vulnerable:
Test Here

For more information on this vulnerability, you can read the whole Secunia advisory here:
http://secunia.com/advisories/24535/


Full topic : New Internet Explorer 7 Spoofing Vulnerability

This post has been edited by HIPPO1023: 16 March 2007 - 09:56 AM


Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users