Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting content from one window into another window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability. NOTE: later research shows that Internet Explorer 7 on Windows XP SP2 is also vulnerable.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2004-12-30 21:00
Updated : 2021-07-23 05:55
NVD link : CVE-2004-1155
Mitre link : CVE-2004-1155
JSON object : View
CWE
Products Affected
microsoft
- internet_explorer
- ie