Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-1499
Description:Microsoft Internet Explorer 7.0 on Windows XP and Vista allows remote attackers to conduct phishing attacks and possibly execute arbitrary code via a res: URI to navcancl.htm with an arbitrary URL as an argument, which displays the URL in the location bar of the "Navigation Canceled" page and injects the script into the "Refresh the page" link, aka Navigation Cancel Page Spoofing Vulnerability."
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-1499
BugTraq ID: 22966
http://www.securityfocus.com/bid/22966
Bugtraq: 20070314 Phishing using IE7 local resource vulnerability (Google Search)
http://www.securityfocus.com/archive/1/462833/100/0/threaded
Bugtraq: 20070315 RE: Phishing using IE7 local resource vulnerability (Google Search)
http://www.securityfocus.com/archive/1/462945/100/0/threaded
Bugtraq: 20070315 Re: Phishing using IE7 local resource vulnerability (Google Search)
http://www.securityfocus.com/archive/1/462939/100/0/threaded
Cert/CC Advisory: TA07-163A
http://www.us-cert.gov/cas/techalerts/TA07-163A.html
HPdes Security Advisory: HPSBST02231
http://www.securityfocus.com/archive/1/471947/100/0/threaded
HPdes Security Advisory: SSRT071438
http://www.securityfocus.com/archive/1/471947/100/0/threaded
http://aviv.raffon.net/2007/03/14/PhishingUsingIE7LocalResourceVulnerability.aspx
http://news.com.com/2100-1002_3-6167410.html
Microsoft Security Bulletin: MS07-033
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-033
http://osvdb.org/35352
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1715
http://securitytracker.com/id?1018235
http://secunia.com/advisories/24535
http://secunia.com/advisories/25627
http://securityreason.com/securityalert/2448
http://www.vupen.com/english/advisories/2007/0946
http://www.vupen.com/english/advisories/2007/2153
XForce ISS Database: ie-navcancl-xss(33026)
https://exchange.xforce.ibmcloud.com/vulnerabilities/33026




© 1998-2025 E-Soft Inc. All rights reserved.