Executive Summary

Informations
Name CVE-2003-1025 First vendor Publication 2004-01-20
Vendor Cve Last vendor Modification 2021-07-23

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Cvss Base Score 4.3 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1025

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-20 Improper Input Validation

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:490
 
Oval ID: oval:org.mitre.oval:def:490
Title: IE v5.01,SP2 Improper URL Canonicalization Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1025
Version: 5
Platform(s): Microsoft Windows 2000
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:491
 
Oval ID: oval:org.mitre.oval:def:491
Title: IE v5.01,SP3 Improper URL Canonicalization Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1025
Version: 5
Platform(s): Microsoft Windows 2000
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:510
 
Oval ID: oval:org.mitre.oval:def:510
Title: IE v5.01,SP4 Improper URL Canonicalization Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1025
Version: 5
Platform(s): Microsoft Windows 2000
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:511
 
Oval ID: oval:org.mitre.oval:def:511
Title: IE v5.5,SP2 Improper URL Canonicalization Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1025
Version: 3
Platform(s): Microsoft Windows ME
Microsoft Windows NT
Microsoft Windows 2000
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:512
 
Oval ID: oval:org.mitre.oval:def:512
Title: IE v6.0 Improper URL Canonicalization Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1025
Version: 4
Platform(s): Microsoft Windows XP
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:513
 
Oval ID: oval:org.mitre.oval:def:513
Title: IE v6.0,SP1 Improper URL Canonicalization Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1025
Version: 5
Platform(s): Microsoft Windows ME
Microsoft Windows NT
Microsoft Windows 2000
Microsoft Windows XP
Product(s): Microsoft Internet Explorer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:526
 
Oval ID: oval:org.mitre.oval:def:526
Title: IE v6.0,SP1 (Server 2003) Improper URL Canonicalization Vulnerability
Description: Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2003-1025
Version: 6
Platform(s): Microsoft Windows Server 2003
Product(s): Microsoft Internet Explorer
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1

ExploitDB Exploits

id Description
2004-02-03 Microsoft Internet Explorer 5 NavigateAndFind() Cross-Zone Policy Vulnerability
2004-02-04 MS Internet Explorer URL Injection in History List (MS04-004)

OpenVAS Exploits

Date Description
2005-11-03 Name : IE 5.01 5.5 6.0 Cumulative patch (890923)
File : nvt/smb_nt_ms02-005.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
3022 Mozilla Status Bar Manipulation Weakness

Mozilla contains a flaw that may lead to an unauthorized information disclosure. It is possible for a user to manipulate information displayed in the status bar, which could be used to trick users who trust the information displayed there, resulting in a loss of confidentiality.
2942 Multiple Browser Domain URL Spoofing

Internet Explorer, Opera, Mozilla and possibly other web browsers contains a flaw that may allow a malicious user to spoof a trusted site. The issue is triggered when a %01 character is placed in a URL. It is possible that the flaw may allow a malicious site to trick an unsuspecting user resulting in a loss of confidentiality and integrity.

Snort® IPS/IDS

Date Description
2014-11-16 Microsoft Internet Explorer URL domain spoof attempt
RuleID : 31888 - Revision : 2 - Type : BROWSER-IE
2014-11-16 Microsoft Internet Explorer URL domain spoof attempt
RuleID : 31887 - Revision : 2 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer URL canonicalization address bar spoofing attempt
RuleID : 15933 - Revision : 8 - Type : BROWSER-IE

Sources (Detail)

Source Url
BUGTRAQ http://www.securityfocus.com/archive/1/346948
CERT http://www.us-cert.gov/cas/techalerts/TA04-033A.html
CERT-VN http://www.kb.cert.org/vuls/id/652278
MISC http://www.zapthedingbat.com/security/ex01/vun1.htm
MS https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04...
OVAL https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/13935

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
Date Informations
2021-07-27 00:24:37
  • Multiple Updates
2021-07-24 01:44:15
  • Multiple Updates
2021-07-24 01:01:36
  • Multiple Updates
2021-07-23 17:24:41
  • Multiple Updates
2021-05-04 12:02:10
  • Multiple Updates
2021-04-22 01:02:18
  • Multiple Updates
2020-05-23 00:15:33
  • Multiple Updates
2018-10-13 00:22:28
  • Multiple Updates
2017-10-11 09:23:19
  • Multiple Updates
2017-07-11 12:01:19
  • Multiple Updates
2016-04-26 12:39:27
  • Multiple Updates
2014-11-16 21:24:18
  • Multiple Updates
2014-01-19 21:22:03
  • Multiple Updates
2013-05-11 11:53:28
  • Multiple Updates