Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-5355

BugsAlert Home > CVE-2007-5355
 
 

The Web Proxy Auto-Discovery (WPAD) feature in Microsoft Internet Explorer 6 and 7, when a primary DNS suffix with three or more components is configured, resolves an unqualified wpad hostname in a second-level domain outside this configured DNS domain, which allows remote WPAD servers to conduct man-in-the-middle (MITM) attacks.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5355

Learn more about CVE-2007-5355
 
Tags: cve-2007-5355

Related Items

      Gervase Markham: Frequent/Intense Huh?

      CVE-2009-3674 (ie, windows_2000, windows_server_2003, windows_xp, windows_server_2008, windows_v...)

      FrSIRT - Fedora Security Update Fixes Horde Multiple Security Bypass Issues

      CVE-2009-0508 (websphere_application_server)

      SFS EZ Top Sites "ts" SQL Injection Vulnerability

      WORM_SPYBOT.GEN

      Mandriva: Subject: [Security Announce] [ MDVSA-2009:217-2 ] mozilla-thunderbird

 

Pixel