Medium severity flaw in Konqueror

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



I was recently taking a look at Konquerer and spotted an example of universal 
XSS.  Essentially, the error page displayed when a requested URL is not 
available includes said URL.  If said URL includes HTML fragments these will 
be rendered.  CVE-2010-2952 has been assigned to this issue.

Tim
-- 
Tim Brown
<mailto:timb@xxxxxxxxxxxxxxxxxxxx>
<http://www.nth-dimension.org.uk/>

Attachment: NDSA20110321.txt.asc
Description: PGP signature

Attachment: signature.asc
Description: This is a digitally signed message part.


[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux