The flaw lies in the way IE7 processes a locally stored HTML (Hypertext Markup Language) error message page that is typically shown when the user cancels the loading of a Web page, said Aviv Raff, a security researcher based in Israel.
The error message tells the user that "navigation to the webpage was cancelled," and offers the user the opportunity to "refresh the page." If the refresh link is clicked, IE can be tricked into displaying the wrong Web address for a page. Raff has published proof of concept code that shows how IE can be made to display a Web page on his Web site as if it is from the cnn.com domain.
This flaw could be exploited by phishers who want to make their spoofed Web sites appear legitimate, Raff said.
IE7 bug could help pishers
Posted on Thursday, March 15 2007 @ 3:06 CET by Thomas De Maesschalck