7.5

CVE-2002-1442

Exploit

The Google toolbar 1.1.58 and earlier allows remote web sites to perform unauthorized toolbar operations including script execution and file reading in other zones such as "My Computer" by opening a window to tools.google.com or the res: protocol, then using script to modify the window's location to the toolbar's configuration URL, which bypasses the origin verification check.

Data is provided by the National Vulnerability Database (NVD)
GoogleToolbar Version1.1.41
GoogleToolbar Version1.1.42
GoogleToolbar Version1.1.43
GoogleToolbar Version1.1.44
GoogleToolbar Version1.1.45
GoogleToolbar Version1.1.47
GoogleToolbar Version1.1.48
GoogleToolbar Version1.1.49
GoogleToolbar Version1.1.53
GoogleToolbar Version1.1.54
GoogleToolbar Version1.1.55
GoogleToolbar Version1.1.56
GoogleToolbar Version1.1.57
GoogleToolbar Version1.1.58
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.68% 0.691
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P