CVE-2010-0315
WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value, related to an IFRAME element.
- Affected products
- Google Chrome, Webkit
- Google Chrome
- ≤ 4.0.249.78, 0.2.149.27, 0.2.149.29, 0.2.149.30, 0.2.152.1, 0.2.153.1, 0.3.154.0, 0.3.154.3, 0.4.154.18, 0.4.154.22, 0.4.154.31, 0.4.154.33, 1.0.154.36, 1.0.154.39, 1.0.154.42, 1.0.154.43, 1.0.154.46, 1.0.154.48, 1.0.154.52, 1.0.154.53, 1.0.154.59, 1.0.154.65, 2.0.156.1, 2.0.157.0, 2.0.157.2, 2.0.158.0, 2.0.159.0, 2.0.169.0, 2.0.169.1, 2.0.170.0, 2.0.172, 2.0.172.2, 2.0.172.8, 2.0.172.27, 2.0.172.28, 2.0.172.30, 2.0.172.31, 2.0.172.33, 2.0.172.37, 2.0.172.38
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 6.9% (93th percentile)
- NVD status
- Modified
- Published
- 2010-01-14
CVE-2010-0315 at NVD
2 known exploits for CVE-2010-0315
Proof-of-concept code and exploit modules indexed by Sploitus