PT-2009-5345 · Lunascape · Lunascape
Lostmon
·
Published
2009-08-28
·
Updated
2017-08-17
·
CVE-2009-3005
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Lunascape versions 5.1.3 through 5.1.4
Description:
The issue allows remote attackers to spoof the address bar via
window.open with a relative URI. This can be used to show an arbitrary URL on the web site visited by the victim. For example, a visit to an attacker-controlled web page can trigger a spoofed login form for the site containing that page. A related attack was reported where an arbitrary file: URL is shown.Recommendations:
For versions 5.1.3 and 5.1.4, consider restricting the use of the
window.open function with relative URIs until a patch is available. As a temporary workaround, avoid using relative URIs in the window.open function to minimize the risk of address bar spoofing.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lunascape