First published: Sun Feb 19 2006(Updated: )
Microsoft Internet Explorer allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page with an anchor element with a legitimate "href" attribute, a form whose action points to a malicious URL, and an INPUT submit element that is modified to look like a legitimate URL. NOTE: this issue is very similar to CVE-2004-1104, although the manipulations are slightly different.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =6.0.2900 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0799 is considered a significant vulnerability due to its potential for phishing attacks.
To mitigate CVE-2006-0799, users should upgrade to a later version of Internet Explorer or implement browser security features.
The impact of CVE-2006-0799 is that it allows attackers to spoof URLs, leading to possible phishing attacks.
CVE-2006-0799 primarily affects users of Microsoft Internet Explorer version 6.0.2900.
Yes, CVE-2006-0799 can be exploited remotely by attackers through specially crafted web pages.