vendor:
N/A
by:
Andreas Sandblad
7,5
CVSS
HIGH
Cross-site Scripting (XSS)
79
CWE
Product Name: N/A
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2004-0206
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2004
Backbutton Exploit
This exploit allows an attacker to inject arbitrary JavaScript code into the history list of a web browser. When the user hits the back button, the code is executed. This demo simply creates a harmless textfile on the desktop.
Mitigation:
The vulnerability can be mitigated by disabling the ability to navigate to a javascript URL.