Google Fixes Its Toolbar Vulnerability
By Olivier Duffez, September 27, 2004 at 10:22 AM in: Google - Comments RSS Feed
Google has just released yesterday a new version of its toolbar (v2.0.114-5) to fix some vulnerabilities. It's not possible anymore to inject code remotely on MS Internet Explorer.
According to SecurityTracker, it was reported that the 'About' section of the Google Toolbar did not properly filter HTML code. A user could create HTML that, when loaded by the target user, will invoke the About page and execute arbitrary scripting code in the context of the page.

Via Inside Google and Dirson.
Related article
- Google updates toolbar versions information - 2004-12-04 11:16







Comments
1. September 27, 2004 at 01:35 PM, by Dodger :: site
2. October 6, 2004 at 12:58 AM, by Netmar :: site
Post a comment
Comments for this post are disabled.