CVE-2001-1410
35Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 51%
from disclosure to weapon0 days
Published on NVDJul 17
1st PoCOct 21
exploitation probability
51%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Internet Explorer 6 and earlier allows remote attackers to create chromeless windows using the Javascript window.createPopup method, which could allow attackers to simulate a victim's display and conduct unauthorized activities or steal sensitive data via social engineering.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/21127⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://marc.info/?l=bugtraq&m=105820229407274&w=2http://marc.info/?l=bugtraq&m=105829174431769&w=2https://exchange.xforce.ibmcloud.com/vulnerabilities/7313http://www.doxdesk.com/personal/posts/bugtraq/20030713-ie/http://www.guninski.com/popspoof.htmlhttp://www.kb.cert.org/vuls/id/490708http://www.securityfocus.com/archive/1/221883http://www.securityfocus.com/bid/3469http://www.systemintegra.com/ie-fullscreen/