WebKit XMLHttpRequest Cookie Information Disclosure Vulnerability
BID:33804
Info
WebKit XMLHttpRequest Cookie Information Disclosure Vulnerability
| Bugtraq ID: | 33804 |
| Class: | Design Error |
| CVE: |
CVE-2008-6059 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 18 2008 12:00AM |
| Updated: | Feb 20 2009 03:47PM |
| Credit: | Robert Sesek |
| Vulnerable: |
WebKit Open Source Project WebKit 0 |
| Not Vulnerable: |
WebKit Open Source Project WebKit r38566 |
Discussion
WebKit XMLHttpRequest Cookie Information Disclosure Vulnerability
WebKit is prone to an information-disclosure vulnerability related to XMLHttpRequest handling.
A successful exploit may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to WebKit r38566 are vulnerable.
WebKit is prone to an information-disclosure vulnerability related to XMLHttpRequest handling.
A successful exploit may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to WebKit r38566 are vulnerable.
Exploit / POC
WebKit XMLHttpRequest Cookie Information Disclosure Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user to visit a malicious webpage.
Attackers can exploit this issue by enticing an unsuspecting user to visit a malicious webpage.
Solution / Fix
WebKit XMLHttpRequest Cookie Information Disclosure Vulnerability
Solution:
The vendor has released updates. Please contact the vendor for details.
Solution:
The vendor has released updates. Please contact the vendor for details.
References
WebKit XMLHttpRequest Cookie Information Disclosure Vulnerability
References:
References:
- Bug 10957: HttpOnly Cookie Option (Robert Sesek)
- Changeset 38566 for trunk/WebCore/xml/XMLHttpRequest.cpp (WebKit)
- WebKit Homepage (WebKit Open Source Project)