HTTP: MS IE OnUnload Javascript Browser Entrapment Address Bar Spoofing
This signature detects attempts to exploit a known vulnerability against Microsoft IE OnUnload. A successful attack could allow the attacker to spoof the source URI of a file presented to an unsuspecting user.
Extended Description
Microsoft Internet Explorer is prone to a vulnerability that allows attackers to trap users at a particular webpage and spoof page transitions. Attackers may exploit this via a malicious page to spoof the contents and origin of a page that the victim may trust. This vulnerability may be useful in phishing or other attacks that rely on content spoofing. NOTE: Mozilla Firefox is likely prone to a variation of this vulnerability. We will update this BID as more information emerges. Internet Explorer 6 and 7 are confirmed vulnerable to this issue.
Affected Products
Nortel_networks contact_center_manager_server
References
BugTraq: 22680
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Nortel_networks
Hp
Microsoft