First published: Wed Jul 13 2005(Updated: )
Microsoft Internet Explorer 6.0 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2274 is considered a medium severity vulnerability due to its potential to facilitate phishing attacks.
To mitigate CVE-2005-2274, it is advisable to upgrade to a more secure web browser or apply security patches that address this vulnerability.
CVE-2005-2274 allows attackers to spoof dialog boxes, leading to increased risks of phishing attacks.
CVE-2005-2274 specifically affects Microsoft Internet Explorer 6.0.
The root cause of CVE-2005-2274 is the lack of clear association between a spoofed Javascript dialog box and the originating web page.