PT-2009-5345 · Lunascape · Lunascape

Lostmon

·

Published

2009-08-28

·

Updated

2017-08-17

·

CVE-2009-3005

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Lunascape versions 5.1.3 through 5.1.4
Description: The issue allows remote attackers to spoof the address bar via window.open with a relative URI. This can be used to show an arbitrary URL on the web site visited by the victim. For example, a visit to an attacker-controlled web page can trigger a spoofed login form for the site containing that page. A related attack was reported where an arbitrary file: URL is shown.
Recommendations: For versions 5.1.3 and 5.1.4, consider restricting the use of the window.open function with relative URIs until a patch is available. As a temporary workaround, avoid using relative URIs in the window.open function to minimize the risk of address bar spoofing.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-3005

Affected Products

Lunascape