CVE-2001-1410: Medium severity Microsoft Internet Explorer vulnerability
Published Jul 17, 2003
·Updated
Internet Explorer 6 and earlier allows remote attackers to create chromeless windows using the Javascript window.createPopup method, which could allow attackers to simulate a victim's display and conduct unauthorized activities or steal sensitive data via social engineering.
Affected Software
4 affected components
Microsoft Internet Explorer=5.5-sp2
Microsoft Internet Explorer=5.5
Microsoft Internet Explorer=5.5-sp1
Microsoft Internet Explorer=6.0
Event History
Jul 17, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1410?
CVE-2001-1410 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2001-1410?
To mitigate CVE-2001-1410, users should upgrade to a later version of Internet Explorer that does not support the vulnerable window.createPopup method.
3
What systems are affected by CVE-2001-1410?
CVE-2001-1410 affects Internet Explorer 5.5 and 6.0.
4
What type of vulnerability is CVE-2001-1410?
CVE-2001-1410 is a security vulnerability related to spoofing attacks.
5
Can attackers exploit CVE-2001-1410 for phishing attacks?
Yes, attackers can use CVE-2001-1410 to simulate a legitimate interface and conduct phishing attacks.