Kaspersky Password Manager HTML Injection Vulnerability
BID:54760
Info
Kaspersky Password Manager HTML Injection Vulnerability
| Bugtraq ID: | 54760 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 01 2012 12:00AM |
| Updated: | Aug 01 2012 12:00AM |
| Credit: | Benjamin Kunz Mejri |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Kaspersky Password Manager HTML Injection Vulnerability
Kaspersky Password Manager is prone to an HTML-injection vulnerability.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Kaspersky Password Manager 5.0.0.164 is vulnerable; other versions may also be affected.
Kaspersky Password Manager is prone to an HTML-injection vulnerability.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Kaspersky Password Manager 5.0.0.164 is vulnerable; other versions may also be affected.
Exploit / POC
Kaspersky Password Manager HTML Injection Vulnerability
Attackers can exploit this issue by enticing a user to visit a crafted URL.
Attackers can exploit this issue by enticing a user to visit a crafted URL.
Solution / Fix
Kaspersky Password Manager HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
References
Kaspersky Password Manager HTML Injection Vulnerability
References:
References: