Google Chrome 'view-source' Address Bar URI Spoofing Vulnerability
BID:51262
Info
Google Chrome 'view-source' Address Bar URI Spoofing Vulnerability
| Bugtraq ID: | 51262 |
| Class: | Design Error |
| CVE: |
CVE-2011-3907 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 13 2011 12:00AM |
| Updated: | Dec 13 2011 12:00AM |
| Credit: | Luka Treiber of ACROS Security |
| Vulnerable: |
Google Chrome 15.0.874 102 Google Chrome 15.0.874.121 Google Chrome 15.0.874.120 Google Chrome 14.0.835.202 Google Chrome 14.0.835.186 Google Chrome 14.0.835.163 Google Chrome 14 |
| Not Vulnerable: |
Google Chrome 16.0.912.63 |
Exploit / POC
Google Chrome 'view-source' Address Bar URI Spoofing Vulnerability
To exploit this issue an attacker must entice an unsuspecting user to follow a maliciously crafted URI.
A few examples and videos demonstrating the attack are available; please see the references.
To exploit this issue an attacker must entice an unsuspecting user to follow a maliciously crafted URI.
A few examples and videos demonstrating the attack are available; please see the references.