Google Toolbar ABOUT.HTML cross-site scripting
| google-toolbar-about-code-execution (17435) |
Description:
The Google Toolbar could allow a remote attacker to execute arbitrary code on the system. A remote attacker, with the ability to access access the 'res:' protocol, could create a specially-crafted Web page that invokes the ABOUT.HTML Web page and contains embedded code, which would be executed in the victim's local computer zone, once the Web page is visited.
Consequences:
Gain Access
Remedy:
No remedy available as of July 9, 2011.
References:
- Full-Disclosure Mailing List, Sat Sep 18 2004 - 12:31:15 CDT: Re: GoogleToolbar:About -- Allows Script Injection.
- BID-11210: Google Toolbar About.HTML HTML Injection Vulnerability
- CVE-2004-2475: Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protocol does not cross privilege boundaries, since it is not allowed in the Internet Zone. Thus this might not be a vulnerability.
- OSVDB ID: 10037: Google Toolbar About Page Cross-Domain Command Execution
- SECTRACK ID: 1011351: Google Toolbar Input Validation Hole in `About` Page Lets Local Users Execute Scripting Code
Platforms Affected:
- Google Toolbar 1.1.41
- Google Toolbar 1.1.42
- Google Toolbar 1.1.43
- Google Toolbar 1.1.44
- Google Toolbar 1.1.45
- Google Toolbar 1.1.47
- Google Toolbar 1.1.48
- Google Toolbar 1.1.49
- Google Toolbar 1.1.53
- Google Toolbar 1.1.54
- Google Toolbar 1.1.55
- Google Toolbar 1.1.56
- Google Toolbar 1.1.57
- Google Toolbar 1.1.58
- Google Toolbar 1.1.59
- Google Toolbar 1.1.60
- Google Toolbar 2.0.114.1
Reported:
Sep 17, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
