CVE-2007-3164

Microsoft Internet Explorer 7 - Info Disclosure

Title source: llm
STIX 2.1

Description

Microsoft Internet Explorer 7, when prompting for HTTP Basic Authentication for an IDN web site, uses ACE labels for the domain name in the status bar, but uses internationalized labels for this name in the authentication dialog, which might allow remote attackers to perform phishing attacks if the user misinterprets confusable characters in the internationalized labels, as demonstrated by displaying xn--theshmogroup-bgk.com only in the status bar.

References (6)

Core 6
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25663
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/36142
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34867
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24483

Scores

EPSS 0.0985
EPSS Percentile 95.1%

Details

Status published
Products (1)
microsoft/internet_explorer 7.0
Published Jun 11, 2007
Tracked Since Feb 18, 2026