This script is Copyright (C) 2011-2013 Tenable Network Security, Inc.
The remote FreeBSD host is missing one or more security-related
A class of bugs affecting many web browsers in the same way was
discovered. A Secunia advisory reports :
The problem is that the browsers don't check if a target frame belongs
to a website containing a malicious link, which therefore doesn't
prevent one browser window from loading content in a named frame in
Successful exploitation allows a malicious website to load arbitrary
content in an arbitrary frame in another browser window owned by e.g.
a trusted site.
A KDE Security Advisory reports :
A malicious website could abuse Konqueror to insert its own frames
into the page of an otherwise trusted website. As a result the user
may unknowingly send confidential information intended for the trusted
website to the malicious website.
Secunia has provided a demonstration of the vulnerability at
See also :
Update the affected packages.
Risk factor :
High / CVSS Base Score : 7.5