Google Toolbar Input Validation Hole in 'About' Page Lets Local Users Execute Scripting Code

it seems google toolbar about Us page has some scripting error which is highly vulnerable, Following message was posting in the security tracker site,



Date: Fri, 17 Sep 2004 09:51:10 +0100 (BST)From: ViPeR Subject: GoogleToolbar:About -- Allows Script Injection


Affection Software : GoogleToolbar
Version : Tested on 2.0.114.1-big/en (GGLD)

Notes:
GoogleToolbar's About section allows injection of
script, since it lacks any checking. The following
code is a Proof Of Concept.




rgds,
Gregory R. Panakkal / Viper


0 Comments:

Post a Comment

Links to this post:

Create a Link

<< SEO Blog Home