Slim Browser Cross-Domain Tab Window Form Field Focus Vulnerability
BID:11530
Info
Slim Browser Cross-Domain Tab Window Form Field Focus Vulnerability
| Bugtraq ID: | 11530 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2004 12:00AM |
| Updated: | Oct 26 2004 12:00AM |
| Credit: | Reported to affect Slim Browser by Claudio Cabaleiro, original issue disclosed by Secunia Research. |
| Vulnerable: |
FlashPeak Slim Browser 4.01.003 FlashPeak Slim Browser 4.01 FlashPeak Slim Browser 4 |
| Not Vulnerable: | |
Discussion
Slim Browser Cross-Domain Tab Window Form Field Focus Vulnerability
A cross-domain tab window form field focus vulnerability reportedly affects Slim Browser. This issue is due to an access validation error that allows a web page to gain access to form fields in other web pages rendered in different tabs of the same browser window.
This issue may be leveraged to facilitate convincing phishing style attacks designed to reveal sensitive information such as passwords and financial details.
A cross-domain tab window form field focus vulnerability reportedly affects Slim Browser. This issue is due to an access validation error that allows a web page to gain access to form fields in other web pages rendered in different tabs of the same browser window.
This issue may be leveraged to facilitate convincing phishing style attacks designed to reveal sensitive information such as passwords and financial details.
Exploit / POC
Slim Browser Cross-Domain Tab Window Form Field Focus Vulnerability
An exploit is not required.
A proof of concept is available from the following location:
http://secunia.com/multiple_browsers_form_field_focus_test/
An exploit is not required.
A proof of concept is available from the following location:
http://secunia.com/multiple_browsers_form_field_focus_test/
Solution / Fix
Slim Browser Cross-Domain Tab Window Form Field Focus Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Slim Browser Cross-Domain Tab Window Form Field Focus Vulnerability
References:
References:
- Multiple Browsers Tabbed Browsing Vulnerabilities (Secunia)
- Slim Browser Homepage (FlashPeak)