Jump to content

Google Toolbar Vulnerability


Recommended Posts

Posted

Google Toolbar Input Validation Hole in 'About' Page Lets Remote Users Execute Scripting Code in the Local Computer Zone

SecurityTracker Alert ID: 1011351

SecurityTracker URL: http://securitytracker.com/id?1011351

CVE Reference: GENERIC-MAP-NOMATCH (Links to External Site)

Date: Sep 17 2004

Impact: Execution of arbitrary code via network, User access via network

Exploit Included: Yes

Version(s): Tested on 2.0.114.1-big/en (GGLD)

Description: Input validation vulnerability in the Google Toolbar. A remote user can execute arbitrary scripting code in the Local Computer security zone.

It is reported that the 'About' section of the Google Toolbar does not properly filter HTML code. A remote user can create HTML that, when loaded by the target user, will invoke the About page and execute arbitrary scripting code in the context of the page.

A demonstration exploit is provided:

<script>
window.showModalDialog("res://C:\\Program%20Files\\Google\\GoogleToolbar1.dll/ABOUT.HTML",
"<div style=\"background-image:
url(javascript:alert(location.href));\">");
<script>

Impact: A remote user can cause scripting code to be executed in the Local Computer security zone.

Solution: No solution was available at the time of this entry.

Vendor URL: toolbar.google.com/ (Links to External Site)

Cause: Input validation error

Underlying OS: Windows (Any)

Source: http://www.securitytracker.com/


Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...