First published: Wed Oct 29 2008(Updated: )
Microsoft Internet Explorer 6 omits high-bit URL-encoded characters when displaying the address bar, which allows remote attackers to spoof the address bar via a URL with a domain name that differs from an important domain name only in these characters, as demonstrated by using exam%A9ple.com to spoof example.com, aka MSRC ticket MSRC7900.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4788 has been rated as a medium severity vulnerability.
CVE-2008-4788 allows attackers to spoof the address bar, potentially leading to phishing attacks.
CVE-2008-4788 specifically affects Microsoft Internet Explorer 6.
Users should upgrade to a newer version of Internet Explorer or switch to a different browser.
There is no patch available for CVE-2008-4788, as it is an unpatched issue in an outdated browser.