First published: Mon Feb 26 2007(Updated: )
Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via onUnload Javascript handlers.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =6.0-sp1 | |
Microsoft Internet Explorer | =6.0-sp2 | |
Microsoft Internet Explorer | =7.0 | |
Internet Explorer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1091 is considered a critical vulnerability that allows remote attackers to exploit Internet Explorer's handling of certain JavaScript events.
To fix CVE-2007-1091, users should upgrade to the latest version of Internet Explorer or apply the recommended security patches from Microsoft.
CVE-2007-1091 affects Microsoft Internet Explorer versions 6.0 SP1, 6.0 SP2, and 7.0.
Using CVE-2007-1091, attackers can prevent users from leaving a site, spoof the address bar, and carry out phishing attacks.
Users should refrain from visiting untrusted websites and ensure their browsers are updated to mitigate the risks associated with CVE-2007-1091.