Google Toolbar Unauthorized JavaScript Configuration Modification Vulnerability
BID:5424
Info
Google Toolbar Unauthorized JavaScript Configuration Modification Vulnerability
| Bugtraq ID: | 5424 |
| Class: | Design Error |
| CVE: |
CVE-2002-1442 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 2002 12:00AM |
| Updated: | Jul 11 2009 02:56PM |
| Credit: | Published by GreyMagic Software <[email protected]>. |
| Vulnerable: |
Google Toolbar 1.1.58 Google Toolbar 1.1.57 Google Toolbar 1.1.56 Google Toolbar 1.1.55 Google Toolbar 1.1.54 Google Toolbar 1.1.53 Google Toolbar 1.1.49 Google Toolbar 1.1.48 Google Toolbar 1.1.47 Google Toolbar 1.1.45 Google Toolbar 1.1.44 Google Toolbar 1.1.43 Google Toolbar 1.1.42 Google Toolbar 1.1.41 |
| Not Vulnerable: |
Google Toolbar 1.1.60 Google Toolbar 1.1.59 |
Discussion
Google Toolbar Unauthorized JavaScript Configuration Modification Vulnerability
The Google Toolbar is an ActiveX control for Microsoft Internet Explorer, which provides functionality related to the Google search engine.
It is possible to modify configuration settings by visiting a specific URL that accepts commands as CGI parameters. A malicious script may directly access this URL by redirecting a page which references a trusted site, such as the google.com domain. It is possible to modify the toolbar configuration, and to execute arbitrary script code, possibly within the Local System security zone.
The Google Toolbar is an ActiveX control for Microsoft Internet Explorer, which provides functionality related to the Google search engine.
It is possible to modify configuration settings by visiting a specific URL that accepts commands as CGI parameters. A malicious script may directly access this URL by redirecting a page which references a trusted site, such as the google.com domain. It is possible to modify the toolbar configuration, and to execute arbitrary script code, possibly within the Local System security zone.