Lucene search

K
cve[email protected]CVE-2007-1499
HistoryMar 17, 2007 - 10:19 a.m.

CVE-2007-1499

2007-03-1710:19:00
CWE-79
web.nvd.nist.gov
45
microsoft
internet explorer
ie 7.0
vulnerability
phishing
code execution
nvd
cve-2007-1499

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

7.2 High

AI Score

Confidence

Low

0.959 High

EPSS

Percentile

99.5%

Microsoft Internet Explorer 7.0 on Windows XP and Vista allows remote attackers to conduct phishing attacks and possibly execute arbitrary code via a res: URI to navcancl.htm with an arbitrary URL as an argument, which displays the URL in the location bar of the “Navigation Canceled” page and injects the script into the “Refresh the page” link, aka Navigation Cancel Page Spoofing Vulnerability."

Affected configurations

NVD
Node
microsoftwindows_vista
AND
microsoftieMatch7.0vista
Node
microsoftwindows_xp
AND
microsoftieMatch7.0vista
CPENameOperatorVersion
microsoft:iemicrosoft ieeq7.0

References

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

7.2 High

AI Score

Confidence

Low

0.959 High

EPSS

Percentile

99.5%