Netscape Communicator "date:" Code Injection Vulnerability
BID:323
Info
Netscape Communicator "date:" Code Injection Vulnerability
| Bugtraq ID: | 323 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 06 1999 12:00AM |
| Updated: | Jun 06 1999 12:00AM |
| Credit: | This vulnerability was published in the BUGTRAQ mailing list by Georgi Guninski <[email protected]>. |
| Vulnerable: |
Netscape Communicator 4.51 Netscape Communicator 4.6 Netscape Communicator 4.5 Netscape Communicator 4.0 Netscape Communicator 4.07 Netscape Communicator 4.06 |
| Not Vulnerable: | |
Discussion
Netscape Communicator "date:" Code Injection Vulnerability
A vulnerability in Netscape Communicator allows sniffing URLs from other windows.
The vulnerability is in the injection of JavaScript code in the JavaScript console using the "data:" protocol. Access to document.links is disallowed in version 4.6, but the document may be read using find().
A vulnerability in Netscape Communicator allows sniffing URLs from other windows.
The vulnerability is in the injection of JavaScript code in the JavaScript console using the "data:" protocol. Access to document.links is disallowed in version 4.6, but the document may be read using find().
Exploit / POC
Netscape Communicator "date:" Code Injection Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Netscape Communicator "date:" Code Injection Vulnerability
Solution:
Disable Javascript.
Solution:
Disable Javascript.
References
Netscape Communicator "date:" Code Injection Vulnerability
References:
References:
- "data:" protocol tracking (Georgi Guninski
)