CVE-2004-1104
published 2004-12-31CVE-2004-1104: Microsoft Internet Explorer 6.0 SP2 allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page that…
PriorityP431high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
35.32%
98.3th percentile
Microsoft Internet Explorer 6.0 SP2 allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page that contains a BASE element that points to the legitimate site, followed by an anchor (a) element with an empty "href" attribute, and a FORM whose action points to a malicious URL, and an INPUT submit element that is modified to look like a legitimate URL.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | ie | — | — |
| microsoft | internet_explorer | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pp5h-86c8-pfvc: Microsoft Internet Explorer allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page with an a
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2006-0799 [HIGH] GHSA-pp5h-86c8-pfvc: Microsoft Internet Explorer allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page with an a
Microsoft Internet Explorer allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page with an anchor element with a legitimate "href" attribute, a form whose action points to a malicious URL, and an INPUT submit element that is modified to look like a legitimate URL. NOTE: this issue is very similar to CVE-2004-1104, although the manipulations are slightly different.
GHSA
GHSA-9pp9-78gm-f2c2: Microsoft Internet Explorer 6
ghsa_unreviewed·2022-04-29
CVE-2004-1104 [HIGH] GHSA-9pp9-78gm-f2c2: Microsoft Internet Explorer 6
Microsoft Internet Explorer 6.0 SP2 allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page that contains a BASE element that points to the legitimate site, followed by an anchor (a) element with an empty "href" attribute, and a FORM whose action points to a malicious URL, and an INPUT submit element that is modified to look like a legitimate URL.
No detection rules found.
http://secunia.com/advisories/11273http://www.kb.cert.org/vuls/id/702086http://www.securityfocus.com/archive/1/379903http://www.securityfocus.com/archive/1/425386/100/0/threadedhttp://www.securityfocus.com/archive/1/425883/100/0/threadedhttp://www.securityfocus.com/bid/11565https://exchange.xforce.ibmcloud.com/vulnerabilities/17938http://secunia.com/advisories/11273http://www.kb.cert.org/vuls/id/702086http://www.securityfocus.com/archive/1/379903http://www.securityfocus.com/archive/1/425386/100/0/threadedhttp://www.securityfocus.com/archive/1/425883/100/0/threadedhttp://www.securityfocus.com/bid/11565https://exchange.xforce.ibmcloud.com/vulnerabilities/17938
2004-12-31
Published