Multiple Vendor Browser Bookmark JavaScript Vulnerability
BID:248
Info
Multiple Vendor Browser Bookmark JavaScript Vulnerability
| Bugtraq ID: | 248 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 09 1999 12:00AM |
| Updated: | May 09 1999 12:00AM |
| Credit: | This published in the BUGTRAQ mailing list by Georgi Guninski <[email protected]>. |
| Vulnerable: |
Netscape Communicator 4.51 Microsoft Internet Explorer 5.0 for Windows 98 Microsoft Internet Explorer 5.0 for Windows 95 |
| Not Vulnerable: |
Microsoft Internet Explorer 5.0 for Windows NT 4 |
Discussion
Multiple Vendor Browser Bookmark JavaScript Vulnerability
A vulnerability in Internet Explorer and Netscape Communicator allow Javascript embedded in bookmarks to execute in the context of the document opened prior to choosing the bookmark. This gives the Javascript code access to objects in the same domain.
For example is the last active document is a local file ("file:") the the Javascript in the bookmark would have access to local files.
A vulnerability in Internet Explorer and Netscape Communicator allow Javascript embedded in bookmarks to execute in the context of the document opened prior to choosing the bookmark. This gives the Javascript code access to objects in the same domain.
For example is the last active document is a local file ("file:") the the Javascript in the bookmark would have access to local files.
Exploit / POC
Multiple Vendor Browser Bookmark JavaScript Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple Vendor Browser Bookmark JavaScript Vulnerability
Solution:
Disable Javascript in the browser. Do not bookmark untrusted web pages.
Solution:
Disable Javascript in the browser. Do not bookmark untrusted web pages.
References
Multiple Vendor Browser Bookmark JavaScript Vulnerability
References:
References:
- IE 5.0 "Favorities" vulnerability (Georgi Guninski
) - Netscape Communicator bookmark vulnerabilities (Georgi Guninski
)