KDE Konqueror IFRAME Cross-Domain Scripting Vulnerability
BID:11552
Info
KDE Konqueror IFRAME Cross-Domain Scripting Vulnerability
| Bugtraq ID: | 11552 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 27 2004 12:00AM |
| Updated: | Oct 27 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Yanosz <[email protected]> |
| Vulnerable: |
KDE Konqueror 3.2.2 -6 KDE Konqueror 3.2.1 KDE Konqueror 3.1.4 |
| Not Vulnerable: |
KDE Konqueror 3.3.1 KDE Konqueror 3.3 KDE Konqueror 3.2.3 |
Discussion
KDE Konqueror IFRAME Cross-Domain Scripting Vulnerability
Konqueror is reported prone to a cross-domain scripting vulnerability. The issue is reported to exist because Konqueror fails to prevent JavaScript that is rendered in one frame from accessing properties of a site contained in an alternate frame.
This vulnerability may be exploited by a malicious web site to render JavaScript in the context of an alternate domain.
Konqueror is reported prone to a cross-domain scripting vulnerability. The issue is reported to exist because Konqueror fails to prevent JavaScript that is rendered in one frame from accessing properties of a site contained in an alternate frame.
This vulnerability may be exploited by a malicious web site to render JavaScript in the context of an alternate domain.
Exploit / POC
KDE Konqueror IFRAME Cross-Domain Scripting Vulnerability
A proof of concept is available at the following location:
http://groenndemon.de/bla
A proof of concept is available at the following location:
http://groenndemon.de/bla
Solution / Fix
KDE Konqueror IFRAME Cross-Domain Scripting Vulnerability
Solution:
It is reported that this vulnerability was addressed in KDE Konqueror version 3.2.3.
Solution:
It is reported that this vulnerability was addressed in KDE Konqueror version 3.2.3.