Fenrir Sleipnir 2.9.6 and earlier does not prevent interaction between web script and the clipboard, which allows remote attackers to read or modify the clipboard contents via a crafted web site.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://jvndb.jvn.jp/en/contents/2010/JVNDB-2010-000057.html | third party advisory |
http://www.osvdb.org/69604 | vdb entry |
http://secunia.com/advisories/42427 | third party advisory vendor advisory |
http://fenrir-inc.blogspot.com/2010/11/vulnerability-regarding-allow-paste.html | patch |
http://jvn.jp/en/jp/JVN64764004/index.html | third party advisory |
http://www.fenrir.co.jp/blog/2010/11/post_47.html | patch |