First published: Fri Dec 10 2004(Updated: )
Netscape 7.x to 7.2, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netscape Navigator | =7.1 | |
Netscape Navigator | =7.2 | |
Netscape Navigator | =7.0 | |
Netscape Navigator | =7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1160 is classified as a medium severity vulnerability due to its potential to facilitate phishing attacks.
To mitigate CVE-2004-1160, upgrading to a later version of Netscape Navigator or switching to a different browser is recommended.
CVE-2004-1160 allows remote attackers to conduct phishing attacks by injecting malicious content into trusted sites.
CVE-2004-1160 affects Netscape Navigator versions 7.0 through 7.2.
Yes, CVE-2004-1160 can be exploited without user awareness, making it a significant security concern.