secniche.org
http://www.secniche.org/gcr_clkj CVE-2009-0374
Google Chrome 1.0.154.43 - Clickjacking
Record summary
CVE-2009-0374 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Google Chrome 1.0.154.43 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Clickjacking" vulnerability. NOTE: a third party disputes the relevance of this issue, stating that "every sufficiently featured browser is and likely will remain susceptible to the behavior known as clickjacking," and adding that the exploit code "is not a valid demonstration of the issue.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGoogle Chrome 1.0.154.43 - ClickjackingExploitDB exploitby x0xNot analyzed1 file
References
520090128 Advisory: Google Chrome 1.0.154.43 ClickJacking Vulnerability.mailing list
http://www.securityfocus.com/archive/1/500499/100/0/threaded 20090128 Re: Advisory: Google Chrome 1.0.154.43 ClickJacking Vulnerability.mailing list
http://www.securityfocus.com/archive/1/500533/100/0/threaded nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-0374 7903exploit
https://www.exploit-db.com/exploits/7903