The Google toolbar 1.1.58 and earlier allows remote web sites to monitor a user's input into the toolbar via an "onkeydown" event handler.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/ntbugtraq/2002-q3/0066.html | mailing list |
http://online.securityfocus.com/archive/1/286527 | patch vendor advisory mailing list exploit |
http://sec.greymagic.com/adv/gm001-mc/ | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/10054 | vdb entry |
http://toolbar.google.com/whatsnew.php3 | |
http://www.securityfocus.com/bid/5426 | patch vendor advisory vdb entry exploit |