Chrome Universal XSS by polluting private scripts with named properties (CVE-2017-5008)

Basic Fields

SSV ID:
SSV-92997
Find Time:
Unknown
Submit Time:
2017-04-21
Level:
Category:
通用跨站脚本
Component:
Google Chrome
Author:
Unknown
Submitter:
Knownsec
CVE-ID:
CVE-2017-5008
CNNVD-ID:
Add
CNVD-ID:
Add
ZoomEye Dork:
Add

Source

Detail

Contributor Knownsec Got  0KB
Loading icon
have 0  exchange

PoC

Unavailable PoC

Reference Linking

Solutions

Temp Solutions

Unavailable Temp Solutions

Official Solution

Unavailable Official solution

Defense Solutions

Unavailable Defense Solutions

Popularity 1146
Need to bind phone before comment. Bind Now

All Comments (1)

  • When a private script method is invoked, a ScriptForbiddenScope::AllowUserAgentScript scope is set up to allow running the internal script. It is possible to exploit this scope to execute user code here:
    1F

※Any content provided by this site, only to learn the code and services, not for illegal purposes