Oval Definition:
oval:org.mitre.oval:def:2162
Revision Date
:
2014-02-24
Version
:
46
Title
:
Address Bar Spoofing Vulnerability
Description
:
Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via onUnload Javascript handlers.
Family
:
windows
Class
:
vulnerability
Status
:
ACCEPTED
Reference(s)
:
CVE-2007-1091
Platform(s)
:
Microsoft Windows 2000
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows XP
Product(s)
:
Microsoft Internet Explorer
Definition Synopsis
IE 5.01,SP4 on Win2k,SP4
Microsoft Windows 2000 SP4 or later is installed
AND
Microsoft Internet Explorer 5.01 SP4 is installed
AND
the version of mshtml.dll is less than 5.0.3856.1700
OR
IE 6 on Win 2k, SP4
Microsoft Windows 2000 SP4 or later is installed
AND
Internet Explorer 6 Service Pack 1 is installed
AND
the version of mshtml.dll is less than 6.0.2800.1601
OR
IE 6 on Win XP SP2
Microsoft Windows XP SP2 or later is installed
AND
Microsoft Internet Explorer 6 is installed
AND
the version of mshtml.dll is less than 6.0.2900.3199
OR
IE 6 on Win S03 SP1
Microsoft Windows Server 2003 SP1 (x86) is installed
OR
Microsoft Windows Server 2003 (x64) is installed
OR
Microsoft Windows Server 2003 SP1 for Itanium is installed
AND
Microsoft Internet Explorer 6 is installed
AND
the version of mshtml.dll is less than 6.0.3790.2993
OR
IE 6 on Win S03 SP2
Microsoft Windows Server 2003 SP2 (x86) is installed
OR
Microsoft Windows Server 2003 SP2 (x64) is installed
OR
Microsoft Windows Server 2003 (ia64) SP2 is installed
AND
Microsoft Internet Explorer 6 is installed
AND
the version of mshtml.dll is less than 6.0.3790.4134
OR
IE 6 on Win XP SP1 (64-bit)
Microsoft Windows XP SP1 (64-bit) is installed
AND
Microsoft Internet Explorer 6 is installed
AND
the version of mshtml.dll is less than 6.0.3790.2993
OR
IE 6 on Win XP SP2 (64-bit)
Microsoft Internet Explorer 6 is installed
AND
the version of mshtml.dll is less than 6.0.3790.4134
AND
Microsoft Windows XP x64 Edition SP2 is installed
OR
IE 7 on Windows XP and S03
Windows XP or Server 2003 is installed
Microsoft Windows XP SP2 or later is installed
OR
Microsoft Windows XP SP1 (64-bit) is installed
OR
Microsoft Windows Server 2003 SP1 (x86) is installed
OR
Microsoft Windows Server 2003 SP2 (x86) is installed
OR
Microsoft Windows XP x64 Edition SP2 is installed
AND
Microsoft Internet Explorer 7 is installed
AND
the version of mshtml.dll is less than 7.0.6000.16544
OR
IE 7 on Vista
Microsoft Windows Vista is installed
AND
Microsoft Internet Explorer 7 is installed
AND
the version of mshtml.dll is less than 7.0.6000.16546
BACK