CVE-2009-0369: Medium severity Microsoft Internet Explorer vulnerability
Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Clickjacking" vulnerability.
Affected Software
Event History
Frequently Asked Questions
What user interaction is required for exploitation?
An attacker must trick the user into visiting a malicious page and clicking an attacker-controlled element. The onclick action then moves a crafted element to the current mouse position, causing navigation to an arbitrary URL.
Is this exploitable remotely without authentication?
Yes. The supplied vector indicates network-based exploitation with no authentication required, but the attack requires user interaction and has medium attack complexity.
What security impact is identified?
The provided impact information indicates integrity impact only; confidentiality and availability impacts are listed as none. The described outcome is unwanted navigation to an arbitrary URL.