CVE-2007-1499
Microsoft Internet Explorer 7 - NavCancel.HTM Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Microsoft Internet Explorer 7.0 on Windows XP and Vista allows remote attackers to conduct phishing attacks and possibly execute arbitrary code via a res: URI to navcancl.htm with an arbitrary URL as an argument, which displays the URL in the location bar of the "Navigation Canceled" page and injects the script into the "Refresh the page" link, aka Navigation Cancel Page Spoofing Vulnerability."
Microsoft Internet Explorer versión 7.0 en Windows XP y Vista, permite a los atacantes remotos conducir ataques de phishing y posiblemente ejecutar código arbitrario por medio de un URI res: en el archivo navcancl.htm con una URL arbitraria como argumento, que muestra la URL en la barra de direcciones de la pagina "Navigation Canceled" e inyecta el script hacia el enlace "Refresh the page", también se conoce como "Navigation Cancel Page Spoofing Vulnerability."
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-03-14 First Exploit
- 2007-03-17 CVE Reserved
- 2007-03-17 CVE Published
- 2024-06-20 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (19)
URL | Tag | Source |
---|---|---|
http://news.com.com/2100-1002_3-6167410.html | X_refsource_misc | |
http://osvdb.org/35352 | Vdb Entry | |
http://securityreason.com/securityalert/2448 | Third Party Advisory | |
http://securitytracker.com/id?1018235 | Vdb Entry | |
http://www.securityfocus.com/archive/1/462833/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/462939/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/462945/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/22966 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA07-163A.html | Third Party Advisory | |
http://www.vupen.com/english/advisories/2007/0946 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/2153 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/33026 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1715 | Signature |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/29741 | 2007-03-14 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Ie Search vendor "Microsoft" for product "Ie" | 7.0 Search vendor "Microsoft" for product "Ie" and version "7.0" | vista |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Vista Search vendor "Microsoft" for product "Windows Vista" | * | - |
Safe
|
Microsoft Search vendor "Microsoft" | Ie Search vendor "Microsoft" for product "Ie" | 7.0 Search vendor "Microsoft" for product "Ie" and version "7.0" | vista |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Xp Search vendor "Microsoft" for product "Windows Xp" | * | - |
Safe
|