PT-2010-5175 · Blackberry · Blackberry Device

Publicado

2010-10-14

·

Atualizado

2010-10-15

·

CVE-2010-3934

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions BlackBerry Device Software version 5.0.0.593
Description The browser does not properly restrict cross-domain execution of JavaScript, allowing remote attackers to bypass the Same Origin Policy. This can be achieved via vectors related to a window.open call and an IFRAME element.
Recommendations For BlackBerry Device Software version 5.0.0.593, consider restricting the use of JavaScript in the browser until a patch is available. As a temporary workaround, avoid using the window.open function and IFRAME elements in conjunction, as these are related to the bypassing of the Same Origin Policy.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-3934

Produtos afetados

Blackberry Device