CVE-2007-1091
published 2007-02-26CVE-2007-1091: Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via…
PriorityP423medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
24.80%
97.7th percentile
Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via onUnload Javascript handlers.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | ie | — | — |
| microsoft | ie | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7g9f-9xqr-fxrg: Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other atta
ghsa_unreviewed·2022-05-01
CVE-2007-1091 [MEDIUM] GHSA-7g9f-9xqr-fxrg: Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other atta
Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via onUnload Javascript handlers.
GHSA
GHSA-xpp7-fcx9-3jh8: Microsoft Internet Explorer 5
ghsa_unreviewed·2022-05-01·CVSS 6.8
CVE-2007-3892 [MEDIUM] CWE-94 GHSA-xpp7-fcx9-3jh8: Microsoft Internet Explorer 5
Microsoft Internet Explorer 5.01 through 7 allows remote attackers to spoof the URL address bar and other "trust UI" components via unspecified vectors, a different issue than CVE-2007-1091 and CVE-2007-3826.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lcamtuf.coredump.cx/ietraphttp://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052630.htmlhttp://secunia.com/advisories/23014http://securityreason.com/securityalert/2291http://securitytracker.com/id?1018788http://www.securityfocus.com/archive/1/461023/100/0/threadedhttp://www.securityfocus.com/archive/1/461027/100/0/threadedhttp://www.securityfocus.com/archive/1/482366/100/0/threadedhttp://www.securityfocus.com/bid/22680http://www.us-cert.gov/cas/techalerts/TA07-282A.htmlhttp://www.vupen.com/english/advisories/2007/0713https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-057https://exchange.xforce.ibmcloud.com/vulnerabilities/32647https://exchange.xforce.ibmcloud.com/vulnerabilities/32649https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2162http://lcamtuf.coredump.cx/ietraphttp://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052630.htmlhttp://secunia.com/advisories/23014http://securityreason.com/securityalert/2291http://securitytracker.com/id?1018788http://www.securityfocus.com/archive/1/461023/100/0/threadedhttp://www.securityfocus.com/archive/1/461027/100/0/threadedhttp://www.securityfocus.com/archive/1/482366/100/0/threadedhttp://www.securityfocus.com/bid/22680http://www.us-cert.gov/cas/techalerts/TA07-282A.htmlhttp://www.vupen.com/english/advisories/2007/0713https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-057https://exchange.xforce.ibmcloud.com/vulnerabilities/32647https://exchange.xforce.ibmcloud.com/vulnerabilities/32649https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2162
2007-02-26
Published