Omni Group OmniWeb Browser Remote Window Hijacking Vulnerability
BID:11875
Info
Omni Group OmniWeb Browser Remote Window Hijacking Vulnerability
| Bugtraq ID: | 11875 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 10 2004 12:00AM |
| Updated: | Dec 10 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Secunia Research. |
| Vulnerable: |
Omni Group OmniWeb 5.0.1 |
| Not Vulnerable: | |
Discussion
Omni Group OmniWeb Browser Remote Window Hijacking Vulnerability
OmniWeb is reported prone to a vulnerability that may allow a Web site to hijack the contents of a trusted window. This issue may allow a remote attacker to carry out phishing style attacks.
This issue arises as a user visits a malicious site and follows a link to a trusted site. Once the link to the trusted site is followed, the victim must open a pop up window from the trusted site that can be influenced by the attacker's site.
If successful, the contents of the target site's window can be spoofed resulting in phishing style attacks.
OmniWeb is reported prone to a vulnerability that may allow a Web site to hijack the contents of a trusted window. This issue may allow a remote attacker to carry out phishing style attacks.
This issue arises as a user visits a malicious site and follows a link to a trusted site. Once the link to the trusted site is followed, the victim must open a pop up window from the trusted site that can be influenced by the attacker's site.
If successful, the contents of the target site's window can be spoofed resulting in phishing style attacks.
Exploit / POC
Omni Group OmniWeb Browser Remote Window Hijacking Vulnerability
A proof of concept is available from the following location:
http://secunia.com/multiple_browsers_window_injection_vulnerability_test/
A proof of concept is available from the following location:
http://secunia.com/multiple_browsers_window_injection_vulnerability_test/
Solution / Fix
Omni Group OmniWeb Browser Remote Window Hijacking Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Omni Group OmniWeb Browser Remote Window Hijacking Vulnerability
References:
References:
- OmniWeb Product Page (Omni Group)
- OmniWeb Window Injection Vulnerability (Secunia)