Vulnerability Name: | CVE-2007-3164 (CCN-34867) | ||||||||
Assigned: | 2007-06-08 | ||||||||
Published: | 2007-06-08 | ||||||||
Updated: | 2021-07-23 | ||||||||
Summary: | Microsoft Internet Explorer 7, when prompting for HTTP Basic Authentication for an IDN web site, uses ACE labels for the domain name in the status bar, but uses internationalized labels for this name in the authentication dialog, which might allow remote attackers to perform phishing attacks if the user misinterprets confusable characters in the internationalized labels, as demonstrated by displaying xn--theshmogroup-bgk.com only in the status bar. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N) 4.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N/E:U/RL:U/RC:UR)
2.1 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-3164 Source: CCN Type: ha.ckers Web site Internet Explorer Cross Domain Basic Auth Phishing Tactics Source: MISC Type: UNKNOWN http://ha.ckers.org/blog/20070608/cross-domain-basic-auth-phishing-tactics/ Source: OSVDB Type: UNKNOWN 36142 Source: CCN Type: SA25663 Microsoft Internet Explorer 7 HTTP Basic Authentication IDN Spoofing Source: SECUNIA Type: UNKNOWN 25663 Source: MISC Type: UNKNOWN http://www.bitsploit.de/archives/428-Cross-Domain-Basic-Auth-Phishing-Tactics.html Source: CCN Type: Microsoft Corporation Web site Microsoft Corporation Source: CCN Type: OSVDB ID: 36142 Microsoft IE IDN Site Basic Authentication Status Bar Truncation Spoofing Source: BID Type: UNKNOWN 24483 Source: CCN Type: BID-24483 Microsoft Internet Explorer 7 HTTP Authentication International Domain Name Spoofing Weakness Source: XF Type: UNKNOWN ie-idn-authentication-spoofing(34867) Source: XF Type: UNKNOWN ie-idn-authentication-spoofing(34867) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |