CVE-2017-17692

Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the innerHTML property.
Configurations

Configuration 1 (hide)

cpe:2.3:a:samsung:internet_browser:5.4.02.3:*:*:*:*:*:*:*

History

21 Nov 2024, 03:18

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/145510/Samsung-Internet-Browser-SOP-Bypass.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/145510/Samsung-Internet-Browser-SOP-Bypass.html - Exploit, Third Party Advisory, VDB Entry
References () https://datarift.blogspot.in/p/samsung-interent-browser-sop-bypass-cve.html - Exploit, Third Party Advisory () https://datarift.blogspot.in/p/samsung-interent-browser-sop-bypass-cve.html - Exploit, Third Party Advisory
References () https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/samsung_browser_sop_bypass.rb - Exploit, Third Party Advisory () https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/samsung_browser_sop_bypass.rb - Exploit, Third Party Advisory
References () https://www.exploit-db.com/exploits/43376/ - Exploit, Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/43376/ - Exploit, Third Party Advisory, VDB Entry

Information

Published : 2017-12-21 19:29

Updated : 2025-04-20 01:37


NVD link : CVE-2017-17692

Mitre link : CVE-2017-17692

CVE.ORG link : CVE-2017-17692


JSON object : View

Products Affected

samsung

  • internet_browser
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor