Cross-application scripting vulnerability in the Browser URL loading functionality in Android 2.3.4 and 3.1 allows local applications to bypass the sandbox and execute arbitrary Javascript in arbitrary domains by (1) causing the MAX_TAB number of tabs to be opened, then loading a URI to the targeted domain into the current tab, or (2) making two startActivity function calls beginning with the targeted domain's URI followed by the malicious Javascript while the UI focus is still associated with the targeted domain.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:28
Type | Values Removed | Values Added |
---|---|---|
References | () http://android.git.kernel.org/?p=platform/cts.git%3Ba=commit%3Bh=7e48fb87d48d27e65942b53b7918288c8d740e17 - | |
References | () http://android.git.kernel.org/?p=platform/packages/apps/Browser.git%3B%20a=commit%3Bh=096bae248453abe83cbb2e5a2c744bd62cdb620b - | |
References | () http://android.git.kernel.org/?p=platform/packages/apps/Browser.git%3B%20a=commit%3Bh=afa4ab1e4c1d645e34bd408ce04cadfd2e5dae1e - | |
References | () http://blog.watchfire.com/files/advisory-android-browser.pdf - | |
References | () http://blog.watchfire.com/wfblog/2011/08/android-browser-cross-application-scripting-cve-2011-2357.html - | |
References | () http://osvdb.org/74260 - | |
References | () http://seclists.org/fulldisclosure/2011/Aug/9 - | |
References | () http://secunia.com/advisories/45457 - | |
References | () http://securityreason.com/securityalert/8335 - | |
References | () http://securitytracker.com/id?1025881 - | |
References | () http://www.infsec.cs.uni-saarland.de/projects/android-vuln/ - | |
References | () http://www.infsec.cs.uni-saarland.de/projects/android-vuln/android_xss.pdf - | |
References | () http://www.securityfocus.com/archive/1/519146/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/48954 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/68937 - |
07 Nov 2023, 02:07
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
References | () http://securityreason.com/securityalert/8335 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/68937 - | |
References | () http://securitytracker.com/id?1025881 - | |
References | () http://seclists.org/fulldisclosure/2011/Aug/9 - | |
References | () http://secunia.com/advisories/45457 - | |
References | () http://www.securityfocus.com/bid/48954 - | |
References | () http://www.infsec.cs.uni-saarland.de/projects/android-vuln/android_xss.pdf - | |
References | () http://osvdb.org/74260 - | |
References | () http://www.securityfocus.com/archive/1/519146/100/0/threaded - | |
References | () http://blog.watchfire.com/wfblog/2011/08/android-browser-cross-application-scripting-cve-2011-2357.html - | |
References | () http://blog.watchfire.com/files/advisory-android-browser.pdf - | |
References | () http://www.infsec.cs.uni-saarland.de/projects/android-vuln/ - |
Information
Published : 2011-08-12 18:55
Updated : 2024-11-21 01:28
NVD link : CVE-2011-2357
Mitre link : CVE-2011-2357
CVE.ORG link : CVE-2011-2357
JSON object : View
Products Affected
- android
CWE
CWE-20
Improper Input Validation