Summary
This host is installed with Google Chrome and is prone to information disclosure vulnerability.
Impact
Successful exploitation will let the attacker execute arbitrary codes in the context of the web browser and can reveal sensitive information of the remote user through the web browser.
Solution
No solution or patch was made available for at least one year since disclosure of this vulnerability. Likely none will be provided anymore. General solution options are to upgrade to a newer release, disable respective features, remove the product or replace the product by another one.
For updates refer to http://googlechromereleases.blogspot.com
Insight
This flaw is due to cross-domain information disclosure vulnerability as the web browser fails to properly enforce the same-origin policy.
Affected
Google Chrome version 1.0.154.43 and prior.
References
Severity
Classification
-
CVE CVE-2008-5915 -
CVSS Base Score: 2.1
AV:N/AC:H/Au:S/C:N/I:P/A:N
Related Vulnerabilities
- OTRS Email Message XSS Vulnerability
- phpLDAPadmin 'server_id' Parameter Cross Site Scripting Vulnerabilities
- Manx Multiple Cross Site Scripting and Directory Traversal Vulnerabilities
- Apache Tomcat 'MemoryUserDatabase' Information Disclosure Vulnerability
- Interchange HTTP Response Splitting Vulnerability