Netscape Remote Window Hijacking Vulnerability
BID:11852
Info
Netscape Remote Window Hijacking Vulnerability
| Bugtraq ID: | 11852 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2004 12:00AM |
| Updated: | Dec 08 2004 12:00AM |
| Credit: | Original discovery of the issue is credited to Secunia Research. Juha-Matti Laurio identified this issue in Netscape. |
| Vulnerable: |
Netscape Netscape 7.0 Netscape Navigator 7.2 Netscape Navigator 7.1 Netscape Navigator 7.0.2 Netscape Navigator 7.0 |
| Not Vulnerable: | |
Discussion
Netscape Remote Window Hijacking Vulnerability
Netscape is reported prone to a vulnerability that may allow a Web site to hijack the contents of a trusted window. This issue may allow a remote attacker to carry out phishing style attacks.
This issue arises as a user visits a malicious site and follows a link to a trusted site. Once the link to the trusted site is followed, the victim must open a pop up window from the trusted site that can be influenced by the attacker's site.
If successful, the contents of the target site's window can be spoofed resulting in phishing style attacks.
Netscape is reported prone to a vulnerability that may allow a Web site to hijack the contents of a trusted window. This issue may allow a remote attacker to carry out phishing style attacks.
This issue arises as a user visits a malicious site and follows a link to a trusted site. Once the link to the trusted site is followed, the victim must open a pop up window from the trusted site that can be influenced by the attacker's site.
If successful, the contents of the target site's window can be spoofed resulting in phishing style attacks.
Exploit / POC
Netscape Remote Window Hijacking Vulnerability
A proof of concept is available from the following location:
http://secunia.com/multiple_browsers_window_injection_vulnerability_test/
A proof of concept is available from the following location:
http://secunia.com/multiple_browsers_window_injection_vulnerability_test/
Solution / Fix
Netscape Remote Window Hijacking Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Netscape Remote Window Hijacking Vulnerability
References:
References:
- Netscape Homepage (Netscape)
- Netscape Window Injection Vulnerability (Secunia)