Oval Definition:oval:org.mitre.oval:def:513
Revision Date:2014-02-24Version:45
Title:IE v6.0,SP1 Improper URL Canonicalization Vulnerability
Description:Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2003-1025
Platform(s):Microsoft Windows 2000
Microsoft Windows ME
Microsoft Windows NT
Microsoft Windows XP
Product(s):Microsoft Internet Explorer
Definition Synopsis
  • Internet Explorer 6 Service Pack 1 is installed
  • AND the version of mshtml.dll is less than 6.0.2800.1400
  • AND NOT the patch q832894 is installed (Installed Components key)
  • BACK