Vulnerabilities > CVE-2004-0843 - Unspecified vulnerability in Microsoft IE and Internet Explorer

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
microsoft

Summary

Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."

Vulnerable Configurations

Part Description Count
Application
Microsoft
2

Oval

  • accepted2014-02-24T04:03:12.898-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameJohn Hoyland
      organizationCentennial Software
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:2487
    statusaccepted
    submitted2004-10-25T04:00:00.000-04:00
    titleIE v6.0 Plug-in Navigation Address Bar Spoofing Vulnerability
    version68
  • accepted2014-02-24T04:03:13.018-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:2537
    statusaccepted
    submitted2004-10-25T05:29:00.000-04:00
    titleIE v5.01,SP4 Plug-in Navigation Address Bar Spoofing Vulnerability
    version67
  • accepted2014-02-24T04:03:17.653-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:3949
    statusaccepted
    submitted2005-01-18T12:00:00.000-04:00
    titleIE v5.01, SP3 Plug-in Navigation Address Bar Spoofing Vulnerability
    version67
  • accepted2014-02-24T04:03:24.919-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:6313
    statusaccepted
    submitted2004-10-25T12:00:00.000-04:00
    titleIE v6.0,SP1 for Server 2003 Plug-in Navigation Address Bar Spoofing Vulnerability
    version68
  • accepted2014-02-24T04:03:25.812-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:7095
    statusaccepted
    submitted2004-10-25T05:31:00.000-04:00
    titleIE v5.5,SP2 Plug-in Navigation Address Bar Spoofing Vulnerability
    version67
  • accepted2014-02-24T04:03:26.063-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:7194
    statusaccepted
    submitted2004-10-25T07:44:00.000-04:00
    titleIE v6.0,SP1 Plug-in Navigation Address Bar Spoofing Vulnerability
    version68