vendor:
Facebook for Android
by:
SecurityFocus
3,3
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: Facebook for Android
Affected Version From: 1.8.1
Affected Version To: 1.8.1
Patch Exists: YES
Related CWE: N/A
CPE: a:facebook:facebook_for_android
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Android
2013
Facebook for Android Information Disclosure Vulnerability
Facebook for Android is prone to an information-disclosure vulnerability. Successful exploits allows an attacker to gain access to sensitive information. Information obtained may aid in further attacks. Attacker's app (activity) creates a continuation_intent to call FacebookWebViewActivity and puts a URL pointing to malicious local file. Attacker's HTML/JavaScript file contains a script to get access token from Facebook app and send it to attacker's server.
Mitigation:
Update to the latest version of Facebook for Android.