Vulnerable Software:
The weakness is confirmed in Internet Explorer 7 on a fully patched Windows XP SP2 system.
It is possible to display a popup with a somewhat spoofed address bar where a number of special characters have been appended to the URL. This makes it possible to only display a part of the address bar, which may trick users into performing certain unintended actions.