September 27, 2004
Google Fixes Its Toolbar Vulnerability
By Olivier Duffez, September 27, 2004 at 10:22 AM in: Google
Google has just released yesterday a new version of its toolbar (v2.0.114-5) to fix some vulnerabilities. It's not possible anymore to inject code remotely on MS Internet Explorer.
According to SecurityTracker, it was reported that the 'About' section of the Google Toolbar did not properly filter HTML code. A user could create HTML that, when loaded by the target user, will invoke the About page and execute arbitrary scripting code in the context of the page.

Via Inside Google and Dirson.
Related article
- Google updates toolbar versions information - 2004-12-04 11:16
2 comments
-
no trackback
Read what others are saying about this post on Bloglines, or on Feedster or on Technorati.





