PT-2013-3648 · Fenrir · Sleipnir Mobile+1
Keita Haga
·
Publicado
2013-04-16
·
Atualizado
2013-04-16
·
CVE-2013-2304
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Sleipnir Mobile application versions 2.8.0 and earlier
Sleipnir Mobile Black Edition application versions 2.8.0 and earlier
Description
The issue allows remote attackers to load arbitrary Extension APIs, and trigger downloads or obtain sensitive HTTP response-body information, via a crafted web page.
Recommendations
For Sleipnir Mobile application versions 2.8.0 and earlier, consider restricting access to Extension APIs until a patch is available.
For Sleipnir Mobile Black Edition application versions 2.8.0 and earlier, consider restricting access to Extension APIs until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sleipnir Mobile
Sleipnir Mobile Black Edition