KDE Konqueror 4.1 Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
BID:33085
Info
KDE Konqueror 4.1 Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
| Bugtraq ID: | 33085 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 02 2009 12:00AM |
| Updated: | Jan 05 2009 05:42PM |
| Credit: | athos |
| Vulnerable: |
KDE Konqueror 4.1 |
| Not Vulnerable: | |
Discussion
KDE Konqueror 4.1 Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
KDE Konqueror is prone to multiple cross-site scripting vulnerabilities and multiple denial-of-service vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, or cause the affected browser to crash.
KDE Konqueror 4.1 is vulnerable; other versions may also be affected.
KDE Konqueror is prone to multiple cross-site scripting vulnerabilities and multiple denial-of-service vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, or cause the affected browser to crash.
KDE Konqueror 4.1 is vulnerable; other versions may also be affected.
Exploit / POC
KDE Konqueror 4.1 Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting user into following a malicious URI.
The following example URIs are available
An attacker can exploit these issues by enticing an unsuspecting user into following a malicious URI.
The following example URIs are available
Solution / Fix
KDE Konqueror 4.1 Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
KDE Konqueror 4.1 Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
References:
References:
- Konqueror Homepage (KDE)