Tarun Posted September 18, 2004 Posted September 18, 2004 Google Toolbar Input Validation Hole in 'About' Page Lets Remote Users Execute Scripting Code in the Local Computer Zone SecurityTracker Alert ID: 1011351 SecurityTracker URL: http://securitytracker.com/id?1011351 CVE Reference: GENERIC-MAP-NOMATCH (Links to External Site) Date: Sep 17 2004 Impact: Execution of arbitrary code via network, User access via networkExploit Included: Yes Version(s): Tested on 2.0.114.1-big/en (GGLD) Description: Input validation vulnerability in the Google Toolbar. A remote user can execute arbitrary scripting code in the Local Computer security zone. It is reported that the 'About' section of the Google Toolbar does not properly filter HTML code. A remote user can create HTML that, when loaded by the target user, will invoke the About page and execute arbitrary scripting code in the context of the page.A demonstration exploit is provided:<script>window.showModalDialog("res://C:\\Program%20Files\\Google\\GoogleToolbar1.dll/ABOUT.HTML","<div style=\"background-image:url(javascript:alert(location.href));\">");<script>Impact: A remote user can cause scripting code to be executed in the Local Computer security zone.Solution: No solution was available at the time of this entry.Vendor URL: toolbar.google.com/ (Links to External Site) Cause: Input validation error Underlying OS: Windows (Any) Source: http://www.securitytracker.com/
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now