Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pw5v-pxf7-g2j2

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Google Chrome 1.0.x does not cancel timeouts upon a page transition, which makes it easier for attackers to conduct Universal XSS attacks by calling setTimeout to trigger future execution of JavaScript code, and then modifying document.location to arrange for JavaScript execution in the context of an arbitrary web site. NOTE: this can be leveraged for a remote attack by exploiting a chromehtml: argument-injection vulnerability.

Google Chrome 1.0.x does not cancel timeouts upon a page transition, which makes it easier for attackers to conduct Universal XSS attacks by calling setTimeout to trigger future execution of JavaScript code, and then modifying document.location to arrange for JavaScript execution in the context of an arbitrary web site. NOTE: this can be leveraged for a remote attack by exploiting a chromehtml: argument-injection vulnerability.

EPSS

Процентиль: 50%
0.00264
Низкий

Связанные уязвимости

nvd
почти 17 лет назад

Google Chrome 1.0.x does not cancel timeouts upon a page transition, which makes it easier for attackers to conduct Universal XSS attacks by calling setTimeout to trigger future execution of JavaScript code, and then modifying document.location to arrange for JavaScript execution in the context of an arbitrary web site. NOTE: this can be leveraged for a remote attack by exploiting a chromehtml: argument-injection vulnerability.

debian
почти 17 лет назад

Google Chrome 1.0.x does not cancel timeouts upon a page transition, w ...

EPSS

Процентиль: 50%
0.00264
Низкий