Orca Browser browser:home Persistent XSS vulnerability
Page 1 of 1
Orca Browser browser:home Persistent XSS vulnerability
###########################################
Orca Browser browser:home Persistent XSS vulnerability
vendor url: http://www.orcabrowser.com/
vendor notify: NO exploit available: yes
############################################
#############
description
#############
Orca Browser´s user-friendly interface brings a new level
of clarity and efficiency to your browsing experience,and
frequent upgrades have steadily improved its reliability.
Avant Browser is freeware That's right. 100% Free!.
Orca Browser contains a flaw that allows a remote cross site
scripting attack.This flaw exists because the application does
not validate properly the url links upon submission to the
bookmarks in browser:home page.
This could allow a user to create a specially crafted URL or a
bookmark that would execute arbitrary code in a user's browser
within the trust relationship between the browser and the server
wen try to load browser:home ,leading to a loss of integrity.
###############
version tested
###############
Avant Browser 1.2 build 2
#########
solution:
##########
Update to version 1.2. build 3
this version address this vulnerability.
#############
timeline:
#############
discovered: 23-jul-2009
disclosure: 30 jul 2009
##################
testing
##################
Demostration Video => http://www.spymac.com/details/?2417793
Open Orca Browser and by default the browser load
'browser:home' page. in this page we can view tree
columns , 1 top sites 2 history and 3 recent bookmarks.
Bookmarks column is vulnerable to a xss. let´s go
to demostrate.
I make a web page posible vulnerable to a xss condition
<?
$cmd=$_GET[id]
?>
I place a online doc for demo here =>
http://usuarios.lycos.es/reyfuss/id.php?id=
open Orca browser and navigate to
http://usuarios.lycos.es/reyfuss/id.php?id="><script>alert(1)</script>
click in bookmark Tool bar and click in new bookmark and add this url.
Load browser:home or close and open the browser , the script
is executed in bookmarks column.
################ End #####################
andry- Moderator
- Posts : 467
Join date : 2010-05-07
Similar topics
» Avant Browser browser:home Persistent XSS vulnerabilities
» How Unique Is Your Web Browser?
» Browser Security
» Browser Forensics v1 2010
» Browser Security Handbook
» How Unique Is Your Web Browser?
» Browser Security
» Browser Forensics v1 2010
» Browser Security Handbook
Page 1 of 1
Permissions in this forum:
You cannot reply to topics in this forum