CVE
- Id
- 807
- CVE No.
- CVE-1999-0827
- Status
- Candidate
- Description
- By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.
- Phase
- Proposed (19991208)
- Votes
- ACCEPT(4) Armstrong, Baker, LeBlanc, Stracener | MODIFY(2) Cole, Frech | REVIEWING(1) Prosser
- Comments
- Cole> The BID is 855. If I have the right vulnerability, this allows an | attacker to access URL"s of there choosing which could lead to a compromise | of private information. | Frech> XF:http-frame-spoof | Question: Similar vulnerability to MS98-020 / CVE-1999-0869? | LeBlanc> MSRC tells me this is patched in MS00-009