>> Microsoft Internet Explorer Flash File Loading Address Bar Spoofing Vulnerability
Title : Microsoft Internet Explorer Flash File Loading Address Bar Spoofing Vulnerability VUPEN ID : VUPEN/ADV-2006-1218 CVE ID : CVE-2006-1626
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-04-04
Technical Description
A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by malicious web sites to conduct spoofing and phishing attacks. This flaw is due to an error when loading a Macromedia Flash file (".swf") and a web site in the same browser "window" using the "window.open" method, which could be exploited by remote attackers to spoof the address bar of the browser, causing a victim user to trust the spoofed domain.