CVE-2003-1025: Input Validation
Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."
Affected Software
Event History
Frequently Asked Questions
Which Internet Explorer versions are affected?
Internet Explorer 5.01 through Internet Explorer 6 SP1 are affected.
What must an attacker do to exploit this issue?
An attacker must entice a user to visit a crafted URL. The URL places a %01 character before an @ sign in the user@domain portion, causing the address bar to hide the remainder of the URL, including the real destination site.
What is the practical impact of successful exploitation?
The issue enables domain spoofing in the browser address bar. A user may believe they are visiting a trusted domain while the URL actually directs them to a different site.