Google Chrome XMLHttpRequest Cookie Information Disclosure Vulnerability
BID:33773
Info
Google Chrome XMLHttpRequest Cookie Information Disclosure Vulnerability
| Bugtraq ID: | 33773 |
| Class: | Design Error |
| CVE: |
CVE-2009-0411 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 28 2009 12:00AM |
| Updated: | Jan 28 2009 12:00AM |
| Credit: | laforge |
| Vulnerable: |
Google Chrome 0.3.154 9 Google Chrome 0.2.149 .30 Google Chrome 0.2.149 .29 Google Chrome 0.2.149 .27 Google Chrome 1.0.154.36 |
| Not Vulnerable: |
Google Chrome 1.0.154.46 |
Discussion
Google Chrome XMLHttpRequest Cookie Information Disclosure Vulnerability
Google Chrome is prone to an information-disclosure vulnerability related to XMLHttpRequest handling.
A successful exploit may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Chrome 1.0.154.46 are vulnerable.
Google Chrome is prone to an information-disclosure vulnerability related to XMLHttpRequest handling.
A successful exploit may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Chrome 1.0.154.46 are vulnerable.
Exploit / POC
Google Chrome XMLHttpRequest Cookie Information Disclosure Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Google Chrome XMLHttpRequest Cookie Information Disclosure Vulnerability
Solution:
The vendor has released updates. Please contact the vendor for details.
Solution:
The vendor has released updates. Please contact the vendor for details.
References
Google Chrome XMLHttpRequest Cookie Information Disclosure Vulnerability
References:
References: