Friday, 3. November 2006, 20:21:51

- Internet Explorer 7 Popup Address Bar Spoofing Weakness
Secunia Advisory: SA22542
Release Date: 2006-10-25
Last Update: 2006-10-31

Critical: Less critical
Impact: Spoofing
Where: From remote
Solution Status: Unpatched
Software: Microsoft Internet Explorer 7.x
CVE reference: CVE-2006-5544 (Secunia mirror)
A weakness has been discovered in Internet Explorer, which can be exploited by malicious people to conduct phishing attacks.
The problem is that it's possible to display a popup with a somewhat spoofed address bar where a number of special characters have been appended to the URL. This makes it possible to only display a part of the address bar, which may trick users into performing certain unintended actions.
Secunia has constructed a demonstration, which is available at:
http://secunia.com/
- Internet Explorer 7 Window Injection Vulnerability
Secunia Advisory: SA22628
Release Date: 2006-10-30

Critical: Moderately critical
Impact: Spoofing
Where: From remote
Solution Status: Unpatched
Software: Microsoft Internet Explorer 7.x
CVE reference: CVE-2004-1155 (Secunia mirror)
A vulnerability has been discovered in Internet Explorer 7, which can be exploited by malicious people to spoof the content of websites.
The problem is that a website can inject content into another site's window if the target name of the window is known. This can e.g. be exploited by a malicious website to spoof the content of a pop-up window opened on a trusted website.
This is related to: SA13251
Secunia has constructed a test, which can be used to check if your browser is affected by this issue: http://secunia.com/
The vulnerability has been confirmed on a fully patched system with Internet Explorer 7.0 and Microsoft Windows XP SP2.
Solution: Do not browse untrusted sites while browsing trusted sites.
- Internet Explorer 7 "mhtml:" Redirection Information Disclosure
Secunia Advisory: SA22477
Release Date: 2006-10-19

Critical: Less critical
Impact: Exposure of sensitive information
Where: From remote
Solution Status: Unpatched
Software: Microsoft Internet Explorer 7.x
A vulnerability has been discovered in Internet Explorer, which can be exploited by malicious people to disclose potentially sensitive information.
The vulnerability is caused due to an error in the handling of redirections for URLs with the "mhtml:" URI handler. This can be exploited to access documents served from another web site.
Secunia has constructed a test, which is available at:
http://secunia.com/
Secunia has confirmed the vulnerability on a fully patched system with Internet Explorer 7.0 and Microsoft Windows XP SP2. Other versions may also be affected.