Konqueror Browser Cross-Domain Dialog Box Spoofing Vulnerability
BID:11477
Info
Konqueror Browser Cross-Domain Dialog Box Spoofing Vulnerability
| Bugtraq ID: | 11477 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 20 2004 12:00AM |
| Updated: | Oct 20 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Jakob Balle of Secunia Research. |
| Vulnerable: |
KDE Konqueror 3.2.2 -6 |
| Not Vulnerable: | |
Discussion
Konqueror Browser Cross-Domain Dialog Box Spoofing Vulnerability
Konqueror Browser is reported prone to a cross-domain dialog box spoofing vulnerability. This issue may allow a remote attacker to carry out phishing style attacks as an attacker may exploit this vulnerability to spoof an interface of a trusted web site.
Konqueror Browser is reported prone to a cross-domain dialog box spoofing vulnerability. This issue may allow a remote attacker to carry out phishing style attacks as an attacker may exploit this vulnerability to spoof an interface of a trusted web site.
Exploit / POC
Konqueror Browser Cross-Domain Dialog Box Spoofing Vulnerability
An exploit is not required.
A proof of concept is available from the following location:
http://secunia.com/multiple_browsers_dialog_box_spoofing_test/
An exploit is not required.
A proof of concept is available from the following location:
http://secunia.com/multiple_browsers_dialog_box_spoofing_test/
Solution / Fix
Konqueror Browser Cross-Domain Dialog Box Spoofing Vulnerability
Solution:
It has been reported that KDE has released Konqueror version 3.3.1 dealing with this issue, although this had yet to be confirmed. Please contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that KDE has released Konqueror version 3.3.1 dealing with this issue, although this had yet to be confirmed. Please contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Konqueror Browser Cross-Domain Dialog Box Spoofing Vulnerability
References:
References:
- Konqueror Homepage (KDE)
- Multiple Browsers Tabbed Browsing Vulnerabilities (Secunia)