jigbrowser+ for Android CVE-2013-2306 Address Bar Spoofing Vulnerability
BID:59552
Info
jigbrowser+ for Android CVE-2013-2306 Address Bar Spoofing Vulnerability
| Bugtraq ID: | 59552 |
| Class: | Design Error |
| CVE: |
CVE-2013-2306 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 26 2013 12:00AM |
| Updated: | Apr 26 2013 12:00AM |
| Credit: | Keita Haga of keitahaga.com |
| Vulnerable: |
Jig.jp co jigbrowser+ 1.6.3 Jig.jp co jigbrowser+ 1.6.2 Jig.jp co jigbrowser+ 1.6 Jig.jp co jigbrowser+ 1.5.5 Jig.jp co jigbrowser+ 1.1.1 Jig.jp co jigbrowser+ 1.0.5 Jig.jp co jigbrowser+ 1.5.0 |
| Not Vulnerable: |
Jig.jp co jigbrowser+ 1.6.4 |
Discussion
jigbrowser+ for Android CVE-2013-2306 Address Bar Spoofing Vulnerability
jigbrowser+ for Android is prone to an address bar spoofing vulnerability.
Attackers may exploit this vulnerability through a malicious page to spoof the contents and origin of a page the victim may trust. Attackers may find this issue useful in phishing or other attacks that rely on content spoofing.
Versions prior to jigbrowser+ for Android 1.6.4 are affected.
jigbrowser+ for Android is prone to an address bar spoofing vulnerability.
Attackers may exploit this vulnerability through a malicious page to spoof the contents and origin of a page the victim may trust. Attackers may find this issue useful in phishing or other attacks that rely on content spoofing.
Versions prior to jigbrowser+ for Android 1.6.4 are affected.
Exploit / POC
jigbrowser+ for Android CVE-2013-2306 Address Bar Spoofing Vulnerability
To exploit this issue an attacker must entice an unsuspecting user to follow a crafted URI.
To exploit this issue an attacker must entice an unsuspecting user to follow a crafted URI.
Solution / Fix
jigbrowser+ for Android CVE-2013-2306 Address Bar Spoofing Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
jigbrowser+ for Android CVE-2013-2306 Address Bar Spoofing Vulnerability
References:
References: