[原文]Cross-site scripting (XSS) vulnerability in Google Toolbar allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protocol does not cross privilege boundaries, since it is not allowed in the Internet Zone. Thus this might not be a vulnerability.



漏洞信息

中危 输入验证
2004-12-31 00:00:00 2005-10-20 00:00:00

漏洞信息 (24607)

Google Toolbar 1.1.x About.HTML HTML Injection Vulnerability (EDBID:24607)
windows remote
2004-09-17 Verified
0 ViperSV
Google Toolbar is reported prone to a HTML injection vulnerability. It is reported that the Google Toolbar 'ABOUT.HTML' page allows the injection of HTML and JavaScript code.

This vulnerability may allow an attacker to inject malicious HTML and script code into the about page of the vulnerable application.

<s c r i p t>
"<div style=\"background-image:
</s c r i p t>		

漏洞信息

Google Toolbar About Page Cross-Domain Command Execution
Remote / Network Access Input Manipulation, Misconfiguration
Loss of Integrity
Exploit Public

漏洞描述

Google Toolbar contains a flaw that allows a cross domain scripting attack. This flaw exists because the application does not validate URI input upon submission to the browser. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and arbitrary IE domain, leading to a loss of integrity.

时间线

2004-09-17 2004-09-17
解决方案

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

