|
|
| |
|
| |
kdelibs: HTML injection
| Package(s): | kdelibs |
CVE #(s): | CVE-2011-1168
|
| Created: | April 12, 2011 |
Updated: | May 31, 2011 |
| Description: |
From the KDE advisory:
When Konqueror cannot fetch a requested URL, it renders an error page with
the given URL. If the URL contains JavaScript or HTML code, this code is
also rendered, allowing for the user to be tricked into visiting a
malicious site or providing credentials to an untrusted party. |
| Alerts: |
|
( Log in to post comments)
|
|
|