{ "id": "CVE-2008-4787", "sourceIdentifier": "cve@mitre.org", "published": "2008-10-29T15:31:35.417", "lastModified": "2018-10-11T20:52:47.887", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "Visual truncation vulnerability in Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar via a URL with a hostname containing many   (Non-Blocking Space character) sequences, which are rendered as whitespace, aka MSRC ticket MSRC7899, a related issue to CVE-2003-1025." }, { "lang": "es", "value": "Una vulnerabilidad de truncamiento visual en Microsoft Internet Explorer versi\u00f3n 6, permite a los atacantes remotos suplantar la barra de direcciones por medio de una direcci\u00f3n URL con un nombre de host que contiene muchos \u00a0 (car\u00e1cter de espacio sin bloqueo), que se renderizan como espacios en blanco, tambi\u00e9n se conoce como el ticket MSRC de MSRC7899, un problema relacionado con el CVE-2003-1025." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:P", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL", "baseScore": 5.8 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 4.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:*", "matchCriteriaId": "693D3C1C-E3E4-49DB-9A13-44ADDFF82507" } ] } ] } ], "references": [ { "url": "http://www.securityfocus.com/archive/1/497825/100/0/threaded", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/archive/1/497827/100/0/threaded", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/bid/31960", "source": "cve@mitre.org", "tags": [ "Exploit" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46234", "source": "cve@mitre.org" } ] }