WebKit 'window.console._inspectorCommandLineAPI' Property Cross Domain Scripting Vulnerability
BID:46809
Info
WebKit 'window.console._inspectorCommandLineAPI' Property Cross Domain Scripting Vulnerability
| Bugtraq ID: | 46809 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2011-0169 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 09 2011 12:00AM |
| Updated: | Mar 09 2011 12:00AM |
| Credit: | Apple |
| Vulnerable: |
WebKit Open Source Project WebKit 1.2.5 WebKit Open Source Project WebKit 1.2.3 WebKit Open Source Project WebKit 1.2.2 WebKit Open Source Project WebKit r77705 WebKit Open Source Project WebKit r52833 WebKit Open Source Project WebKit r52401 WebKit Open Source Project WebKit r51295 WebKit Open Source Project WebKit r38566 WebKit Open Source Project WebKit 1.2.X WebKit Open Source Project WebKit 1.2.2-1 WebKit Open Source Project WebKit 0 Apple Safari 5.0.3 for Windows Apple Safari 5.0.3 Apple Safari 5.0.2 for Windows Apple Safari 5.0.2 Apple Safari 5.0.1 for Windows Apple Safari 5.0.1 Apple Safari 5.0 for Windows Apple Safari 5.0 |
| Not Vulnerable: |
Apple Safari 5.0.4 for Windows Apple Safari 5.0.4 |
Discussion
WebKit 'window.console._inspectorCommandLineAPI' Property Cross Domain Scripting Vulnerability
WebKit is prone to a cross-domain scripting vulnerability because it fails to properly enforce the same-origin policy.
An attacker can exploit this issue to execute arbitrary code in the context of a different domain. Successful exploits may result in privilege escalation.
WebKit is prone to a cross-domain scripting vulnerability because it fails to properly enforce the same-origin policy.
An attacker can exploit this issue to execute arbitrary code in the context of a different domain. Successful exploits may result in privilege escalation.
Exploit / POC
WebKit 'window.console._inspectorCommandLineAPI' Property Cross Domain Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user to visit a malicious website.
Attackers can exploit this issue by enticing an unsuspecting user to visit a malicious website.
Solution / Fix
WebKit 'window.console._inspectorCommandLineAPI' Property Cross Domain Scripting Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
WebKit 'window.console._inspectorCommandLineAPI' Property Cross Domain Scripting Vulnerability
References:
References:
- Safari Homepage (Apple)
- Webkit Homepage (Webkit)