NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Freshly Dug Cross-Site Scripting Hole in Internet Explorer 7

Exercise care when Refreshing a canceled page

By Marius Oiaga, Technology News Editor

16th of March 2007, 07:45 GMT

Adjust text size:



Enlarge picture
If you use Internet Explorer 7 and Internet Explorer 7 on Windows Vista, you might fall in a freshly dug cross-scripting hole. The newly discovered vulnerability impacting Internet Explorer was
reported by security researcher Aviv Raff. "Internet Explorer 7.0 is vulnerable to cross-site scripting in one of its local resources. In combination with a design flaw in this specific local resource it is possible for an attacker to easily conduct phishing attacks against IE7 users," Raff explained.

According to Raff, the vulnerability does not require the exploit of any additional third-party software bundled with IE. Instead, an attacker could potentially open a local resource in the browser via a redirection header and bypass the browser's security restrictions. The Internet Explorer 7 navcancl.htm Cross-Site Scripting vulnerability will not receive a high severity rating from Microsoft, as it does not allow for remote code execution, but it can be used in phishing attacks. In this regard, security company Secunia has labeled it as a Less Critical flaw.

"An input validation error exists in the local resource page "navcancl.htm" when generating the "Refresh the page" link. This can be exploited to inject arbitrary script code to e.g. spoof the contents of an arbitrary site when the user clicks on the "Refresh the page" link," Secunia revealed.

In order for a successful attack to take place, an attacker will have to create a malformed navcancl.htm local resource link together with a script designed to display spoofed content of a trusted website. Internet Explorer uses the navcancl.htm local resource when navigation to a page is canceled. In order for an attack to be performed, the user has to hit the Refresh button in IE.

"When the victim will open the link that was sent by the attacker, a "Navigation Canceled" page will be displayed. The victim will think that there was an error in the site or some kind of a network error and will try to refresh the page. Once he will click on the "Refresh the page." link, The attacker's provided content (e.g. fake login page) will be displayed and the victim will think that he's within the trusted site, because the address bar shows the trusted site's URL," Raff added.

TAGS:

Internet Explorer 7 | Cross-Site Scripting
Read by 1,054 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.7/5) 4 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Firefox Takes Another Bite Out of Internet Explorer

Internet Explorer 8 Unveiled in 62 Days?

Internet Explorer 7 - Scarred By Vulnerabilities

Firefox 2.0 Flaws Outperform the Vulnerabilities in IE7

Mozilla Firefox 3.0 Drops This Spring

The Internet Explorer 7 "Matrix" Has You

Internet Explorer 8.0 Is Cooking Since Early January 2006

IE7 Mark of The Web

IE7 and Firefox 2.0 Share Vulnerabilities

The First Taste of Internet Explorer 8

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM