[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256040

 
 

909

 
 

199103

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2004-0526Date: (C)2004-08-06   (M)2023-12-22


Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
BID-10308
http://marc.info/?l=bugtraq&m=108422905510713&w=2
http://archives.neohapsis.com/archives/bugtraq/2004-05/0161.html
http://www.kurczaba.com/securityadvisories/0405132poc.htm
ie-ahref-url-spoofing(16102)

CPE    18
cpe:/a:microsoft:outlook:2002:sp1
cpe:/a:microsoft:outlook:97
cpe:/a:microsoft:outlook:2002:sp2
cpe:/a:microsoft:outlook_express:4.01:sp2
...

© SecPod Technologies