The Sleipnir Mobile application 2.8.0 and earlier and Sleipnir Mobile Black Edition application 2.8.0 and earlier for Android allow remote attackers to load arbitrary Extension APIs, and trigger downloads or obtain sensitive HTTP response-body information, via a crafted web page.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://jvndb.jvn.jp/jvndb/JVNDB-2013-000033 | third party advisory |
http://jvn.jp/en/jp/JVN02895867/index.html | third party advisory |