Multiple Vendor Web Browser JavaScript Multiple Fields Key Filtering Vulnerability
BID:26669
Info
Multiple Vendor Web Browser JavaScript Multiple Fields Key Filtering Vulnerability
| Bugtraq ID: | 26669 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 01 2007 12:00AM |
| Updated: | Dec 03 2007 06:53PM |
| Credit: | Carl Hardwick is credited with the discovery of this vulnerability. |
| Vulnerable: |
Netscape Navigator 9.0.0.4 Mozilla Firefox 2.0 .9 Mozilla Firefox 2.0 .8 Mozilla Firefox 2.0 .7 Mozilla Firefox 2.0 .6 Mozilla Firefox 2.0 .5 Mozilla Firefox 2.0 .4 Mozilla Firefox 2.0 .3 Mozilla Firefox 2.0 .10 Mozilla Firefox 2.0 .1 Mozilla Firefox 1.5 beta 2 Mozilla Firefox 1.5 beta 1 Mozilla Firefox 1.5 12 Mozilla Firefox 1.5 .8 Mozilla Firefox 1.5 .6 Mozilla Firefox 1.5 Mozilla Firefox 2.0.0.3 Mozilla Firefox 2.0.0.2 Mozilla Firefox 2.0.0.11 Mozilla Firefox 2.0.0.10 Mozilla Firefox 2.0 RC3 Mozilla Firefox 2.0 RC2 Mozilla Firefox 2.0 beta 1 Mozilla Firefox 2.0 Mozilla Firefox 1.5.0.9 Mozilla Firefox 1.5.0.8 Mozilla Firefox 1.5.0.7 Mozilla Firefox 1.5.0.6 Mozilla Firefox 1.5.0.5 Mozilla Firefox 1.5.0.4 Mozilla Firefox 1.5.0.3 Mozilla Firefox 1.5.0.2 Mozilla Firefox 1.5.0.2 Mozilla Firefox 1.5.0.11 Mozilla Firefox 1.5.0.10 Mozilla Firefox 1.5.0.1 Apple Safari 3.0.4 Beta for Windows Apple Safari 3.0.3 Beta for Windows Apple Safari 3.0.3 Beta Apple Safari 3.0.2 Beta for Windows Apple Safari 3.0.2 Beta Apple Safari 3.0.1 Beta for Windows Apple Safari 3.0.1 Beta Apple Safari 1.1 Apple Safari 1.0 Apple Safari 3 Beta for Windows Apple Safari 3 Beta |
| Not Vulnerable: | |
Discussion
Multiple Vendor Web Browser JavaScript Multiple Fields Key Filtering Vulnerability
Multiple web browsers are prone to a JavaScript key-filtering vulnerability because the browsers fail to securely handle keystroke input from users.
Exploiting this issue requires that users manually type sensitive data. This may require substantial typing from targeted users, so attackers will likely use keyboard-based games, blogs, or other similar pages to entice users to enter the required keyboard input.
Multiple web browsers are prone to a JavaScript key-filtering vulnerability because the browsers fail to securely handle keystroke input from users.
Exploiting this issue requires that users manually type sensitive data. This may require substantial typing from targeted users, so attackers will likely use keyboard-based games, blogs, or other similar pages to entice users to enter the required keyboard input.
Exploit / POC
Solution / Fix
Multiple Vendor Web Browser JavaScript Multiple Fields Key Filtering Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple Vendor Web Browser JavaScript Multiple Fields Key Filtering Vulnerability
References:
References:
- Firefox 2.0.0.11 File Focus Stealing vulnerability (Carl Hardwick)
- Mozilla Homepage (Mozilla Foundation)
- Netscape Homepage (Netscape)
- Safari Homepage (Apple)