Google Toolbar Input Validation Hole in 'About' Page Lets Local Users Execute Scripting Code

it seems google toolbar about Us page has some scripting error which is highly vulnerable, Following message was posting in the security tracker site,



Date: Fri, 17 Sep 2004 09:51:10 +0100 (BST)From: ViPeR Subject: GoogleToolbar:About -- Allows Script Injection


Affection Software : GoogleToolbar
Version : Tested on 2.0.114.1-big/en (GGLD)

Notes:
GoogleToolbar's About section allows injection of
script, since it lacks any checking. The following
code is a Proof Of Concept.


rgds,
Gregory R. Panakkal / Viper

                              Earthlink Netscape Netvouz RawSugar Shadows Sphinn StumbleUpon Yahoo MyWeb


0 Comments:

Post a Comment

Links to this post:

Create a Link

<< SEO Blog Home

Live Help/Support/Chat



Poll

which blog you like to read regularly in SEO industry?
Matt Cutts Blog
SEOBook Blog
SEOmoz Blog
Graywolf's SEO Blog
Search Engine Journal Blog
Others


View results




Total Stories