Microsoft Internet Explorer 6.0 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."
Link | Tags |
---|---|
http://secunia.com/advisories/15491 | vendor advisory third party advisory exploit |
http://secunia.com/advisories/15492 | third party advisory vendor advisory |
http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/ | exploit |
http://secunia.com/secunia_research/2005-9/advisory/ | vendor advisory |
http://www.microsoft.com/technet/security/advisory/902333.mspx | vendor advisory |