Galeon < 1.2.7 XMLSerializer Cross-domain Policy Access (deprecated)

medium Nessus Network Monitor Plugin ID 1757

Synopsis

The remote host is using a vulnerable version of the Galeon web browser.

Description

The remote host is using the Galeon web browser. The version used contains a flaw that may allow an attacker to set up a rogue web server which will gain access to the properties of other domains displayed in a frame or iframe.

Solution

Upgrade to Galeon 1.2.7 or higher.

Plugin Details

Severity: Medium

ID: 1757

Family: Web Clients

Published: 8/20/2004

Updated: 6/1/2015

Reference Information

BID: 5766