Description
Microsoft Internet Explorer 7, when prompting for HTTP Basic Authentication for an IDN web site, uses ACE labels for the domain name in the status bar, but uses internationalized labels for this name in the authentication dialog, which might allow remote attackers to perform phishing attacks if the user misinterprets confusable characters in the internationalized labels, as demonstrated by displaying xn--theshmogroup-bgk.com only in the status bar.
References (6)
Core 6
Core References
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/25663
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/36142
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34867
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/24483
Various Sources x_refsource_misc
http://ha.ckers.org/blog/20070608/cross-domain-basic-auth-phishing-tactics/
Various Sources x_refsource_misc
http://www.bitsploit.de/archives/428-Cross-Domain-Basic-Auth-Phishing-Tactics.html
Scores
EPSS
0.0985
EPSS Percentile
95.1%
Details
Status
published
Products (1)
microsoft/internet_explorer
7.0
Published
Jun 11, 2007
Tracked Since
Feb 18, 2026