Логотип exploitDog
bind:CVE-2009-1412
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2009-1412

Количество 3

Количество 3

nvd логотип

CVE-2009-1412

почти 17 лет назад

Argument injection vulnerability in the chromehtml: protocol handler in Google Chrome before 1.0.154.59, when invoked by Internet Explorer, allows remote attackers to determine the existence of files, and open tabs for URLs that do not satisfy the IsWebSafeScheme restriction, via a web page that sets document.location to a chromehtml: value, as demonstrated by use of a (1) javascript: or (2) data: URL. NOTE: this can be leveraged for Universal XSS by exploiting certain behavior involving persistence across page transitions.

CVSS2: 7.8
EPSS: Низкий
debian логотип

CVE-2009-1412

почти 17 лет назад

Argument injection vulnerability in the chromehtml: protocol handler i ...

CVSS2: 7.8
EPSS: Низкий
github логотип

GHSA-xc6f-php3-f47w

почти 4 года назад

Argument injection vulnerability in the chromehtml: protocol handler in Google Chrome before 1.0.154.59, when invoked by Internet Explorer, allows remote attackers to determine the existence of files, and open tabs for URLs that do not satisfy the IsWebSafeScheme restriction, via a web page that sets document.location to a chromehtml: value, as demonstrated by use of a (1) javascript: or (2) data: URL. NOTE: this can be leveraged for Universal XSS by exploiting certain behavior involving persistence across page transitions.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2009-1412

Argument injection vulnerability in the chromehtml: protocol handler in Google Chrome before 1.0.154.59, when invoked by Internet Explorer, allows remote attackers to determine the existence of files, and open tabs for URLs that do not satisfy the IsWebSafeScheme restriction, via a web page that sets document.location to a chromehtml: value, as demonstrated by use of a (1) javascript: or (2) data: URL. NOTE: this can be leveraged for Universal XSS by exploiting certain behavior involving persistence across page transitions.

CVSS2: 7.8
0%
Низкий
почти 17 лет назад
debian логотип
CVE-2009-1412

Argument injection vulnerability in the chromehtml: protocol handler i ...

CVSS2: 7.8
0%
Низкий
почти 17 лет назад
github логотип
GHSA-xc6f-php3-f47w

Argument injection vulnerability in the chromehtml: protocol handler in Google Chrome before 1.0.154.59, when invoked by Internet Explorer, allows remote attackers to determine the existence of files, and open tabs for URLs that do not satisfy the IsWebSafeScheme restriction, via a web page that sets document.location to a chromehtml: value, as demonstrated by use of a (1) javascript: or (2) data: URL. NOTE: this can be leveraged for Universal XSS by exploiting certain behavior involving persistence across page transitions.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу