Jump to content

Recommended Posts

Posted

Google Toolbar Input Validation Hole in 'About' Page Lets Remote Users Execute Scripting Code in the Local Computer Zone

SecurityTracker Alert ID: 1011351

SecurityTracker URL: http://securitytracker.com/id?1011351

CVE Reference: GENERIC-MAP-NOMATCH (Links to External Site)

Date: Sep 17 2004

Impact: Execution of arbitrary code via network, User access via network

Exploit Included: Yes

Version(s): Tested on 2.0.114.1-big/en (GGLD)

Description: Input validation vulnerability in the Google Toolbar. A remote user can execute arbitrary scripting code in the Local Computer security zone.

It is reported that the 'About' section of the Google Toolbar does not properly filter HTML code. A remote user can create HTML that, when loaded by the target user, will invoke the About page and execute arbitrary scripting code in the context of the page.

A demonstration exploit is provided:

<script>
window.showModalDialog("res://C:\\Program%20Files\\Google\\GoogleToolbar1.dll/ABOUT.HTML",
"<div style=\"background-image:
url(javascript:alert(location.href));\">");
<script>

Impact: A remote user can cause scripting code to be executed in the Local Computer security zone.

Solution: No solution was available at the time of this entry.

Vendor URL: toolbar.google.com/ (Links to External Site)

Cause: Input validation error

Underlying OS: Windows (Any)

Source: http://www.securitytracker.com/


Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...