Description
Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting content from one window into another window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability. NOTE: later research shows that Internet Explorer 7 on Windows XP SP2 is also vulnerable.
References (6)
Core 6
Core References
Exploit, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/11855
Vendor Advisory x_refsource_misc
http://secunia.com/multiple_browsers_window_injection_vulnerability_test/
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22628
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/449917/100/0/threaded
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/13251/
Vendor Advisory x_refsource_misc
http://secunia.com/secunia_research/2004-13/advisory/
Scores
EPSS
0.1258
EPSS Percentile
95.9%
Details
Status
published
Products (7)
microsoft/ie
5.0.1 (4 CPE variants)
microsoft/ie
5.2.3
microsoft/ie
6.0 sp1 (2 CPE variants)
microsoft/ie
7.0 windows_xp_sp2
microsoft/internet_explorer
5.0.1 (5 CPE variants)
microsoft/internet_explorer
5.5 (4 CPE variants)
microsoft/internet_explorer
6.0
Published
Dec 31, 2004
Tracked Since
Feb 18, 2026