ICab Web Browser Cross-Domain Dialog Box Spoofing Vulnerability
BID:11531
Info
ICab Web Browser Cross-Domain Dialog Box Spoofing Vulnerability
| Bugtraq ID: | 11531 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2004 12:00AM |
| Updated: | Oct 26 2004 12:00AM |
| Credit: | This issue was reported in iCab by camperslo. Jakob Balle of Secunia Research is the original discoverer of these issues in other browsers. |
| Vulnerable: |
Alexander Clauss & iCab Company iCab 2.9.8 |
| Not Vulnerable: | |
Discussion
ICab Web Browser Cross-Domain Dialog Box Spoofing Vulnerability
iCab is reported prone to a cross-domain dialog box spoofing vulnerability. This issue may allow a remote attacker to carry out phishing style attacks.
An attacker may exploit this vulnerability to spoof an interface of a trusted web site. This vulnerability may aid in phishing style attacks.
iCab 2.9.8 is reported vulnerable to this issue. It is likely that other versions are affected as well.
iCab is reported prone to a cross-domain dialog box spoofing vulnerability. This issue may allow a remote attacker to carry out phishing style attacks.
An attacker may exploit this vulnerability to spoof an interface of a trusted web site. This vulnerability may aid in phishing style attacks.
iCab 2.9.8 is reported vulnerable to this issue. It is likely that other versions are affected as well.
Exploit / POC
ICab Web Browser Cross-Domain Dialog Box Spoofing Vulnerability
An exploit is not required.
A proof of concept is available from the following location:
http://secunia.com/multiple_browsers_dialog_box_spoofing_test/
An exploit is not required.
A proof of concept is available from the following location:
http://secunia.com/multiple_browsers_dialog_box_spoofing_test/
Solution / Fix
ICab Web Browser Cross-Domain Dialog Box Spoofing Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
ICab Web Browser Cross-Domain Dialog Box Spoofing Vulnerability
References:
References:
- iCab Browser Home Page (iCab)
- iCab Dialog Spoofing Vulnerability (Secunia)