PT-2013-3648 · Fenrir · Sleipnir Mobile+1

Keita Haga

·

Publicado

2013-04-16

·

Atualizado

2013-04-16

·

CVE-2013-2304

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Sleipnir Mobile application versions 2.8.0 and earlier Sleipnir Mobile Black Edition application versions 2.8.0 and earlier
Description The issue allows remote attackers to load arbitrary Extension APIs, and trigger downloads or obtain sensitive HTTP response-body information, via a crafted web page.
Recommendations For Sleipnir Mobile application versions 2.8.0 and earlier, consider restricting access to Extension APIs until a patch is available. For Sleipnir Mobile Black Edition application versions 2.8.0 and earlier, consider restricting access to Extension APIs until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-2304

Produtos afetados

Sleipnir Mobile
Sleipnir Mobile Black Edition