Vulnerability Name:

CVE-2001-1410 (CCN-7313)

Assigned:2001-10-21
Published:2001-10-21
Updated:2021-07-23
Summary:Internet Explorer 6 and earlier allows remote attackers to create chromeless windows using the Javascript window.createPopup method, which could allow attackers to simulate a victim's display and conduct unauthorized activities or steal sensitive data via social engineering.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Privileges
References:Source: CCN
Type: BugTraq Mailing List, Sun Jul 13 2003 - 14:20:21 CDT
IE chromeless window vulnerabilities

Source: CCN
Type: BugTraq Mailing List, Mon Jul 14 2003 - 12:41:57 CDT
RE: IE chromeless window vulnerabilities

Source: CCN
Type: BugTraq Mailing List, Mon Jul 12 2004 - 13:20:51 CDT
RE: MSIE Download Window Filename + Filetype Spoofing Vulnerability

Source: MITRE
Type: CNA
CVE-2001-1410

Source: BUGTRAQ
Type: UNKNOWN
20030713 IE chromeless window vulnerabilities

Source: BUGTRAQ
Type: UNKNOWN
20030715 Internet Explorer Full-Screen mode threats

Source: CCN
Type: BugTraq Mailing List, 2003-07-15 14:43:13
Internet Explorer Full-Screen mode threats

Source: MISC
Type: UNKNOWN
http://www.doxdesk.com/personal/posts/bugtraq/20030713-ie/

Source: CCN
Type: Georgi Guninski Security Advisory #50
Javascript in IE may spoof the whole screen

Source: MISC
Type: UNKNOWN
http://www.guninski.com/popspoof.html

Source: CCN
Type: US-CERT VU#490708
Microsoft Internet Explorer window.createPopup() method creates chromeless windows

Source: CERT-VN
Type: US Government Resource
VU#490708

Source: CCN
Type: OSVDB ID: 7776
Microsoft IE Download Window Filename Filetype Spoofing

Source: CCN
Type: OSVDB ID: 7853
Microsoft IE window.createPopup Chromeless Window Spoofing

Source: BUGTRAQ
Type: Exploit, Vendor Advisory
20011021 Javascript in IE may spoof the whole screen

Source: BID
Type: Exploit, Vendor Advisory
3469

Source: CCN
Type: BID-3469
Microsoft Internet Explorer JavaScript Interface Spoofing Vulnerability

Source: CCN
Type: BID-8176
Microsoft Internet Explorer window.createPopup Interface Spoofing Vulnerability

Source: CCN
Type: Marek Bialoglowy SYSTEM INTEGRA Web site
INTERNET EXPLORER FULL-SCREEN MODE FULL OF THREATS

Source: MISC
Type: UNKNOWN
http://www.systemintegra.com/ie-fullscreen/

Source: XF
Type: UNKNOWN
ie-javascript-spoof-dialog(7313)

Source: XF
Type: UNKNOWN
ie-javascript-spoof-dialog(7313)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.5:sp1:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:internet_explorer:5.5:-:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft internet explorer 5.5 sp2
    microsoft internet explorer 6.0
    microsoft internet explorer 5.5
    microsoft internet explorer 5.5 sp1
    microsoft ie 5.5
    microsoft ie 6.0