J-Security Center

Title: NetCaptor Cross-Domain Dialog Box Spoofing Vulnerability

Severity: MODERATE

Description:

NetCaptor is a commercial web browser based on the Microsoft Internet Explorer rendering engine. It supports features such as tabbed browsing, pop-up blocking, and ad blocking.

Reportedly, the vulnerability presents itself as dialog boxes from inactive tabs may appear in other tabs. It is reported that an attacker can exploit this issue by creating a malicious Web site and enticing a user to follow a link to the site. If the user follows the link, the attacker can then trigger this issue by somehow enticing a user to follow another link to a trusted site in a new tab. The attacker can then display a spoofed dialog box to the user that seemingly comes from the trusted site. Typically this dialog box would mimic the legitimate site.

An attacker may exploit this vulnerability to spoof an interface of a trusted web site. This vulnerability may aid in phishing style attacks.

Version 7.5.2 of NetCaptor is reported vulnerable. Other versions may also be affected.

Affected Products:

  • NetCaptor NetCaptor 7.5.2

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.