7296 : Multiple Browser Frame Injection Spoofing
Printer | http://osvdb.org/7296 | Email This | Edit Vulnerability

Views This Week

3

Views All Time

47

Info

Last Modified

5 months ago

Percent Complete

100%

Disclosure

Dec 03, 1998

Discovery

Unknown

Dates

Exploit

Jun 27, 2004

Solution

Unknown

Description

Multiple Web Browsers contain a flaw that may allow a malicious user to spoof the content of websites. The issue is triggered when arbitrary content is loaded from a malicious website in an separate frame in another browser window. It is possible that this flaw may allow content to load that appears to originate from a trusted site, resulting in a loss of integrity.

Classification

Location: Remote/Network Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Available
Disclosure: OSVDB Verified

Technical

While this vulnerability dates back to 1998, many web browsers since then have been coded with this issue. In other cases, some web browsers such as Firefox and Mozilla have fixed the vulnerability and then re-introduced it in later versions.

Solution

Depending upon the vendor, either upgrade to the most recent release or install the available patches, as these solutions have been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround(s): do not visit or follow links from untrusted websites.

Products

Microsoft Corporation
Watch-list
Internet Explorer
Watch-list
5.01
5.5
6.0
Internet Explorer for Mac
Watch-list
5
5.2.3
KDE Project
Watch-list
Konqueror
Watch-list
3.2.1
3.0.x
3.1.x
3.2.0
3.2.2
Mozilla Organization
Watch-list
Firebird
Watch-list
0.7
Firefox
Watch-list
0.9
0.9.1
0.8
1.0.4
Mozilla
Watch-list
1.0
1.1
1.4
1.5
1.6
0.x
1.2
1.3
1.7.8
Camino
Watch-list
0.8.4
0.8.3
Netscape Communications Corporation
Watch-list
Netscape Navigator
Watch-list
6.x
7.0
7.1
Opera Software
Watch-list
Opera
Watch-list
6.x
5.x
7.0x
7.1x
7.2x
7.50x
7.51
Apple Computer, Inc.
Watch-list
Safari
Watch-list
1.0
1.1
1.2
1.2.0
1.2.1
1.2.2
kmeleon.org
Watch-list
K-Meleon
Watch-list
0.8.2
0.9
Hewlett-Packard Development Company, L.P.
Watch-list
OpenVMS Secure Web Browser
Watch-list
1.7.8

References

Tools & Filters

Nessus

14214 14268 14335 14688 14689 14690 14691 14758 15427 15977 15978 15979 15980 15981 16003 16366 18782 18794 19260 19262 19268 19269 19273 19276 19285 19345 19431 19433 19685 19888 20420 20544 20556

Credit

  • Mark Laurence - m.laurenceBrand New Doo Doogroveindependentschool.co.uk -
  • http-equiv - http-equivBrand New Doo Dooexcite.com -
  • Gary McKay -

Blogs

None found at this time

Comments

No Comments.

DONATE NOW!

User Status

Quick Searches

Advertisements

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2008 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use