Back to search
CVE-2001-1410
Published: Jul 17, 2003
Modified: Aug 8, 2024
PUBLISHED
Description
Internet Explorer 6 and earlier allows remote attackers to create chromeless windows using the Javascript window.createPopup method, which could allow attackers to simulate a victim's display and conduct unauthorized activities or steal sensitive data via social engineering.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20030713 IE chromeless window vulnerabilities
mailing-list
x_refsource_BUGTRAQ
ie-javascript-spoof-dialog(7313)
vdb-entry
x_refsource_XF
3469
vdb-entry
x_refsource_BID
20030715 Internet Explorer Full-Screen mode threats
mailing-list
x_refsource_BUGTRAQ
http://www.systemintegra.com/ie-fullscreen/
x_refsource_MISC
VU#490708
third-party-advisory
x_refsource_CERT-VN
20011021 Javascript in IE may spoof the whole screen
mailing-list
x_refsource_BUGTRAQ
http://www.guninski.com/popspoof.html
x_refsource_MISC
http://www.doxdesk.com/personal/posts/bugtraq/20030713-ie/
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now