Overview
Internet Explorer 7 may allow address bar spoofing in pop-up windows. This could let an attacker spoof the address of a web site.
Description
| Internet Explorer 7 includes a new feature called "Address bar protection." This makes sure that every window, including pop-ups, will present an address bar to the user. By using a specially crafted URI, an attacker can spoof this address bar in a pop-up window. | 
Impact
| This vulnerability could be used to convince a user that the intruder's web site was actually a web site that the user trusts and might provide sensitive information to. | 
Solution
| We are currently unaware of a practical solution to this problem. | 
| Disable Active scripting | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
Acknowledgements
This vulnerability was publicly disclosed by Secunia.
This document was written by Will Dormann.
Other Information
| CVE IDs: | None | 
| Severity Metric: | 2.84 | 
| Date Public: | 2006-10-25 | 
| Date First Published: | 2006-10-26 | 
| Date Last Updated: | 2006-10-26 17:55 UTC | 
| Document Revision: | 7 |