Short Name |
HTTP:STC:IE:ONUNLOAD
|
Severity |
Medium
|
Recommended |
No
|
Recommended Action |
Drop
|
Category |
HTTP
|
Keywords |
MS IE OnUnload Javascript Browser Entrapment Address Bar Spoofing
|
Release Date |
2014/03/20
|
Update Number |
2355
|
Supported Platforms |
idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+
|
HTTP: MS IE OnUnload Javascript Browser Entrapment Address Bar Spoofing
This signature detects attempts to exploit a known vulnerability against Microsoft IE OnUnload. A successful attack could allow the attacker to spoof the source URI of a file presented to an unsuspecting user.
Extended Description
Microsoft Internet Explorer is prone to a vulnerability that allows attackers to trap users at a particular webpage and spoof page transitions.
Attackers may exploit this via a malicious page to spoof the contents and origin of a page that the victim may trust. This vulnerability may be useful in phishing or other attacks that rely on content spoofing.
NOTE: Mozilla Firefox is likely prone to a variation of this vulnerability. We will update this BID as more information emerges.
Internet Explorer 6 and 7 are confirmed vulnerable to this issue.
Affected Products
- HP Storage Management Appliance 2.1
- HP Storage Management Appliance I
- HP Storage Management Appliance II
- HP Storage Management Appliance III
- Microsoft Internet Explorer 5.0.1
- Microsoft Internet Explorer 5.0.1 SP1
- Microsoft Internet Explorer 5.0.1 SP2
- Microsoft Internet Explorer 5.0.1 SP3
- Microsoft Internet Explorer 5.0.1 SP4
- Microsoft Internet Explorer 6.0
- Microsoft Internet Explorer 6.0 SP1
- Microsoft Internet Explorer 7.0
- Nortel Networks CallPilot 1002Rp
- Nortel Networks CallPilot 200I
- Nortel Networks CallPilot 201I
- Nortel Networks CallPilot 702T
- Nortel Networks CallPilot 703T
- Nortel Networks Centrex IP Client Manager 7.0.0
- Nortel Networks Centrex IP Client Manager 8.0.0
- Nortel Networks Centrex IP Client Manager 9.0
- Nortel Networks Centrex IP Element Manager 7.0.0
- Nortel Networks Centrex IP Element Manager 8.0.0
- Nortel Networks Centrex IP Element Manager 9.0.0
- Nortel Networks Contact Center
- Nortel Networks Contact Center Administration
- Nortel Networks Contact Center Express
- Nortel Networks Contact Center Manager
- Nortel Networks Contact Center Manager Server
- Nortel Networks Contact Center Multimedia
References