Omni Group OmniWeb Browser Cross-Domain Dialog Box Spoofing Vulnerability
BID:11544
Info
Omni Group OmniWeb Browser Cross-Domain Dialog Box Spoofing Vulnerability
| Bugtraq ID: | 11544 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 27 2004 12:00AM |
| Updated: | Oct 27 2004 12:00AM |
| Credit: | This issue was reported in OmniWeb by Sam. Jakob Balle of Secunia Research is the original discoverer of these issues in other browsers. |
| Vulnerable: |
Omni Group OmniWeb 5.0.1 |
| Not Vulnerable: | |
Discussion
Omni Group OmniWeb Browser Cross-Domain Dialog Box Spoofing Vulnerability
OmniWeb is reported prone to a cross-domain dialog box spoofing vulnerability. This issue may allow a remote attacker to carry out phishing style attacks.
An attacker may exploit this vulnerability to spoof an interface of a trusted web site. This vulnerability may aid in phishing style attacks.
OmniWeb 5.0.1 is reported vulnerable to this issue. It is likely that other versions are affected as well.
OmniWeb is reported prone to a cross-domain dialog box spoofing vulnerability. This issue may allow a remote attacker to carry out phishing style attacks.
An attacker may exploit this vulnerability to spoof an interface of a trusted web site. This vulnerability may aid in phishing style attacks.
OmniWeb 5.0.1 is reported vulnerable to this issue. It is likely that other versions are affected as well.
Exploit / POC
Omni Group OmniWeb Browser Cross-Domain Dialog Box Spoofing Vulnerability
An exploit is not required.
A proof of concept is available from the following location:
http://secunia.com/multiple_browsers_dialog_box_spoofing_test/
An exploit is not required.
A proof of concept is available from the following location:
http://secunia.com/multiple_browsers_dialog_box_spoofing_test/
Solution / Fix
Omni Group OmniWeb Browser Cross-Domain Dialog Box Spoofing Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Omni Group OmniWeb Browser Cross-Domain Dialog Box Spoofing Vulnerability
References:
References:
- OmniWeb Dialog Spoofing Vulnerability (Secunia)
- OmniWeb Product Page (Omni Group)