CVE-2002-1442

The Google toolbar 1.1.58 and earlier allows remote web sites to perform unauthorized toolbar operations including script execution and file reading in other zones such as "My Computer" by opening a window to tools.google.com or the res: protocol, then using script to modify the window's location to the toolbar's configuration URL, which bypasses the origin verification check.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:google:toolbar:1.1.41:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.42:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.43:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.44:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.45:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.47:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.48:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.49:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.53:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.54:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.55:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.56:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.57:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.58:*:*:*:*:*:*:*

History

20 Nov 2024, 23:41

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/ntbugtraq/2002-q3/0066.html - () http://archives.neohapsis.com/archives/ntbugtraq/2002-q3/0066.html -
References () http://online.securityfocus.com/archive/1/286527 - Exploit, Patch, Vendor Advisory () http://online.securityfocus.com/archive/1/286527 - Exploit, Patch, Vendor Advisory
References () http://sec.greymagic.com/adv/gm001-mc/ - () http://sec.greymagic.com/adv/gm001-mc/ -
References () http://www.securityfocus.com/bid/5424 - Exploit, Patch, Vendor Advisory () http://www.securityfocus.com/bid/5424 - Exploit, Patch, Vendor Advisory

Information

Published : 2003-04-11 04:00

Updated : 2024-11-20 23:41


NVD link : CVE-2002-1442

Mitre link : CVE-2002-1442

CVE.ORG link : CVE-2002-1442


JSON object : View

Products Affected

google

  • toolbar