Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:STC:IE:ANCHOR-URL-SPOOF

Severity

Medium

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Microsoft Internet Explorer Nested Anchor Tag Confusion Status Bar Spoofing

Release Date

2013/07/08

Update Number

2280

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Microsoft Internet Explorer Nested Anchor Tag Confusion Status Bar Spoofing


This signature detects attempts to exploit a known vulnerability against Microsoft Internet Explorer. A successful attack could allow an attacker to convince targeted users into visiting malicious sites.

Extended Description

Microsoft Internet Explorer is reported prone to a URI obfuscation weakness. This issue may be leveraged by an attacker to display false information in the status bar of an unsuspecting user, allowing an attacker to present web pages to users that seem to originate from a trusted location. This vulnerability is reported to affect Internet Explorer 6, other versions might also be affected. Update: A report regarding this issue has been disclosed specifying that Internet Explorer version 6.0.2900.2180 may not be affected, or may be affected in a different manner. Symantec has confirmed that version 6.0.2800.1106 of Internet Explorer is vulnerable to this weakness. NOTE: It has been reported that this issue does not affect Internet Explorer for Apple Mac OS X. Update: Internet Explorer version 6.0.2900.2180 running on Windows XP SP2 is reportedly not vulnerable to this issue.

Affected Products

  • Microsoft Internet Explorer 6.0
  • Microsoft Internet Explorer 6.0 SP1

References

  • BugTraq: 11561

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out