KDE Konqueror Lets Remote Users Inject Content into Open Windows
Categorie: Vulnerability Posted: 2004-12-09 by ReCall Views: 507 Source: Click here
Current Rating: Not rated
Details
Description: A vulnerability was reported in KDE Konqueror. A remote user can inject content into an open window in certain cases to spoof web site contents.
Secunia Research reported that if the target name of an open window is known, a remote user can create Javascript that, when loaded by the target user, will display arbitrary content in the opened window. A remote user can exploit this to spoof the content of potentially trusted web sites.