Vulnerabilities > CVE-2004-0844 - Unspecified vulnerability in Microsoft IE 6

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
microsoft

Summary

Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double Byte Character Set Systems Vulnerability."

Vulnerable Configurations

Part Description Count
Application
Microsoft
1

Oval

  • accepted2014-02-24T04:03:12.787-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double Byte Character Set Systems Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:2448
    statusaccepted
    submitted2005-01-18T12:00:00.000-04:00
    titleAddress Bar Spoofing on Double Byte Character Set Systems Vulnerability (Server 2003)
    version68
  • accepted2014-02-24T04:03:27.966-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double Byte Character Set Systems Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:8127
    statusaccepted
    submitted2004-10-25T05:13:00.000-04:00
    titleAddress Bar Spoofing on Double Byte Character Set Systems Vulnerability
    version68