Google Toolbar HTML Injection

High Nessus Network Monitor Plugin ID 2306

Synopsis

The remote host is vulnerable to an HTML injection attack.

Description

The remote host is running a vulnerable version of Google Toolbar. It is reported that versions prior to 2.0.114.2 are vulnerable to an HTML injection issue in the ABOUT.HTML page. An attacker may inject malicious script code in this page. An unsuspecting user viewing this page will have the malicious code executed within a less restricted context.

Solution

Upgrade or patch according to vendor recommendations.

See Also

http://archives.neohapsis.com/archives/bugtraq/2002-08/0133.html

http://archives.neohapsis.com/archives/bugtraq/2004-09/0226.html

Plugin Details

Severity: High

ID: 2306

Family: Web Clients

Published: 2004/09/21

Modified: 2016/01/21

Dependencies: 1735, 8314

Nessus ID: 17656

Risk Information

Risk Factor: High

CVSSv2

Base Score: 7.5

Temporal Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:U/RC:ND

CVSSv3

Base Score: 7.3

Temporal Score: 6.7

Vector: CVSS3#AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS3#E:U/RL:U/RC:X

Vulnerability Information

CPE: cpe:/a:google:toolbar

Reference Information

CVE: CVE-2002-1444, CVE-2002-1442, CVE-2004-2475

BID: 11210, 5477, 5424