Описание
iCab 2.9.8 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."
Ссылки
- ExploitPatchVendor Advisory
- Exploit
- ExploitPatchVendor Advisory
- Exploit
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:alexander_clauss:icab:2.9.8:*:*:*:*:*:*:*
EPSS
Процентиль: 57%
0.00351
Низкий
2.6 Low
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
iCab 2.9.8 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."
EPSS
Процентиль: 57%
0.00351
Низкий
2.6 Low
CVSS2
Дефекты
NVD-CWE-Other