CVE-2010-1422
published 2010-06-11CVE-2010-1422: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle changes to keyboard…
PriorityP425medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
3.01%
86.0th percentile
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle changes to keyboard focus that occur during processing of key press events, which allows remote attackers to force arbitrary key presses via a crafted HTML document.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 4.0.5 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| chrome | < 5.0.375.70 | 5.0.375.70 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rq4x-8v8c-7f6x: WebKit does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets," a different vulne
ghsa_unreviewed·2022-05-17·CVSS 5.8
CVE-2010-2441 [MEDIUM] GHSA-rq4x-8v8c-7f6x: WebKit does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets," a different vulne
WebKit does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets," a different vulnerability than CVE-2010-1126, CVE-2010-1422, and CVE-2010-2295.
GHSA
GHSA-vr29-mm4v-x5ph: page/EventHandler
ghsa_unreviewed·2022-05-13·CVSS 4.3
CVE-2010-2295 [MEDIUM] CWE-20 GHSA-vr29-mm4v-x5ph: page/EventHandler
page/EventHandler.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 does not properly handle a change of the focused frame during the dispatching of keydown, which allows user-assisted remote attackers to redirect keystrokes via a crafted HTML document, aka rdar problem 7018610. NOTE: this might overlap CVE-2010-1422.
GHSA
GHSA-xvcw-f78r-rfc5: WebKit in Apple Safari before 5
ghsa_unreviewed·2022-05-02
CVE-2010-1422 [MEDIUM] GHSA-xvcw-f78r-rfc5: WebKit in Apple Safari before 5
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle changes to keyboard focus that occur during processing of key press events, which allows remote attackers to force arbitrary key presses via a crafted HTML document.
Red Hat
WebKit: Keystrokes sent to hidden frame rather than visible frame due to javascript flaw
vendor_redhat·2010-03-14·CVSS 5.8
CVE-2010-2441 [MEDIUM] WebKit: Keystrokes sent to hidden frame rather than visible frame due to javascript flaw
WebKit: Keystrokes sent to hidden frame rather than visible frame due to javascript flaw
WebKit does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets," a different vulnerability than CVE-2010-1126, CVE-2010-1422, and CVE-2010-2295.
Suricata
ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-1422 [HIGH] ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id ASCII
ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id ASCII"; flow:established,to_server; http.uri; content:"/goster.asp?"; nocase; content:"id="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-1422; reference:url,www.securityfocus.com/bid/22910; classtype:web-application-attack; sid:2004389; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitr
Suricata
ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1422 [HIGH] ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id SELECT
ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id SELECT"; flow:established,to_server; http.uri; content:"/goster.asp?"; nocase; content:"id="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-1422; reference:url,www.securityfocus.com/bid/22910; classtype:web-application-attack; sid:2004385; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitr
Suricata
ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1422 [HIGH] ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id INSERT
ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id INSERT"; flow:established,to_server; http.uri; content:"/goster.asp?"; nocase; content:"id="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-1422; reference:url,www.securityfocus.com/bid/22910; classtype:web-application-attack; sid:2004387; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitr
Suricata
ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1422 [HIGH] ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id UNION SELECT
ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id UNION SELECT"; flow:established,to_server; http.uri; content:"/goster.asp?"; nocase; content:"id="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-1422; reference:url,www.securityfocus.com/bid/22910; classtype:web-application-attack; sid:2004386; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_14, mitre_tactic_id TA0001, mitre_tactic_name Initial
Suricata
ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-1422 [HIGH] ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id DELETE
ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id DELETE"; flow:established,to_server; http.uri; content:"/goster.asp?"; nocase; content:"id="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-1422; reference:url,www.securityfocus.com/bid/22910; classtype:web-application-attack; sid:2004388; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitr
Suricata
ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-1422 [HIGH] ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id UPDATE
ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS fystyq Duyuru Scripti SQL Injection Attempt -- goster.asp id UPDATE"; flow:established,to_server; http.uri; content:"/goster.asp?"; nocase; content:"id="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2007-1422; reference:url,www.securityfocus.com/bid/22910; classtype:web-application-attack; sid:2004390; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre
No public exploits indexed.
Bugzilla
Please update to webkitgtk-1.2.3
bugzilla·2010-07-18·CVSS 10.0
[CRITICAL] Please update to webkitgtk-1.2.3
Please update to webkitgtk-1.2.3
Description of problem:
New version in the stable series of webkitgtk is available.
Version-Release number of selected component (if applicable):
webkitgtk-1.2.0-1.fc12.i686
From the announcement [1]:
"Some of you may have noticed WebKitGTK+ 1.2.2 and 1.2.3 have been uploaded recently. Here’s their announcement =). A quick summary: if you’re running the 1.2.x series upgrade to 1.2.3."
According the announcement It should fix one annoying bug with dragging current build is affected with.
It also includes fixes to various CVEs some of which might be also present in current fedora release. Full list of them is in NEWS file [2].
According to the NEWS it also is API/ABI compatible with current fedora release, so no incompatibility problems should arise fro
Bugzilla
update webkitgtk to 1.2.3
bugzilla·2010-07-16·CVSS 10.0
[CRITICAL] update webkitgtk to 1.2.3
update webkitgtk to 1.2.3
Description of problem:
A new version has been released by upstream so we may rebase to it. See http://www.webkitgtk.org/?page=download
Discussion:
From the NEWS file:
What's new in WebKitGTK+ 1.2.3?
- New stable release, API and ABI compatible with previous 1.2.x
versions;
- Includes a fix to build WebKit with ICU 4.4.1
- The patches to fix the following CVEs are included, thanks to the
work done by Michael Gilbert for the
Debian security team:
CVE-2010-1386 CVE-2010-1392 CVE-2010-1405 CVE-2010-1407
CVE-2010-1416 CVE-2010-1417 CVE-2010-1665 CVE-2010-1418
CVE-2010-1421 CVE-2010-1422 CVE-2010-1501 CVE-2010-1767
CVE-2010-1664 CVE-2010-1758 CVE-2010-1759 CVE-2010-1760
CVE-2010-1761 CVE-2010-1762 CVE-2010-1770 CVE-2010-1771
CVE-2010-1772 CVE-2010-1773 CVE-2010-
Bugzilla
CVE-2010-2441 WebKit: Keystrokes sent to hidden frame rather than visible frame due to javascript flaw
bugzilla·2010-06-25·CVSS 5.8
CVE-2010-2441 [MEDIUM] CVE-2010-2441 WebKit: Keystrokes sent to hidden frame rather than visible frame due to javascript flaw
CVE-2010-2441 WebKit: Keystrokes sent to hidden frame rather than visible frame due to javascript flaw
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-2441 to
the following vulnerability:
WebKit does not properly restrict focus changes, which allows remote
attackers to read keystrokes via "cross-domain IFRAME gadgets," a
different vulnerability than CVE-2010-1126, CVE-2010-1422, and
CVE-2010-2295.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2441
[2] https://bugzilla.mozilla.org/show_bug.cgi?id=552255
Discussion:
Created attachment 426888
Local copy of public PoC from Mozilla upstream bug [2]
http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2010//Sep/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2010/Jun/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/40105http://secunia.com/advisories/40196http://secunia.com/advisories/41856http://secunia.com/advisories/42314http://secunia.com/advisories/43068http://securitytracker.com/id?1024067http://support.apple.com/kb/HT4196http://support.apple.com/kb/HT4220http://support.apple.com/kb/HT4334http://support.apple.com/kb/HT4456http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.securityfocus.com/bid/40620http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/1373http://www.vupen.com/english/advisories/2010/1512http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0552https://bugzilla.mozilla.org/show_bug.cgi?id=552255https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7591http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2010//Sep/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2010/Jun/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/40105http://secunia.com/advisories/40196http://secunia.com/advisories/41856http://secunia.com/advisories/42314http://secunia.com/advisories/43068http://securitytracker.com/id?1024067http://support.apple.com/kb/HT4196http://support.apple.com/kb/HT4220http://support.apple.com/kb/HT4334http://support.apple.com/kb/HT4456http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.securityfocus.com/bid/40620http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/1373http://www.vupen.com/english/advisories/2010/1512http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0552https://bugzilla.mozilla.org/show_bug.cgi?id=552255https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7591
2010-06-11
Published