CVE-2010-3115
published 2010-08-24CVE-2010-3115: Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not properly implement the history feature, which might allow remote attackers to spoof the…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.81%
76.5th percentile
Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not properly implement the history feature, which might allow remote attackers to spoof the address bar via unspecified vectors.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| chrome | < 5.0.375.127 | 5.0.375.127 | |
| webkitgtk | webkitgtk | < 1.2.6 | 1.2.6 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ph5f-gjj4-8w92: Google Chrome before 5
ghsa_unreviewed·2022-05-13
CVE-2010-3115 [MEDIUM] GHSA-ph5f-gjj4-8w92: Google Chrome before 5
Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not properly implement the history feature, which might allow remote attackers to spoof the address bar via unspecified vectors.
Red Hat
webkit: address bar spoofing with history bug
vendor_redhat·2010-08-19·CVSS 5.0
CVE-2010-3115 [MEDIUM] webkit: address bar spoofing with history bug
webkit: address bar spoofing with history bug
Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not properly implement the history feature, which might allow remote attackers to spoof the address bar via unspecified vectors.
Suricata
ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0224 [HIGH] ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname SELECT
ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname SELECT"; flow:established,to_server; http.uri; content:"/shopgiftregsearch.asp?"; nocase; content:"LoginLastname="; nocase; content:"SELECT"; nocase; pcre:"/SELECT.+FROM/i"; reference:cve,CVE-2007-0224; reference:url,www.milw0rm.com/exploits/3115; classtype:web-application-attack; sid:2005669; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic
Suricata
ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0224 [HIGH] ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname UNION SELECT
ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname UNION SELECT"; flow:established,to_server; http.uri; content:"/shopgiftregsearch.asp?"; nocase; content:"LoginLastname="; nocase; content:"UNION"; nocase; pcre:"/UNION\s+SELECT/i"; reference:cve,CVE-2007-0224; reference:url,www.milw0rm.com/exploits/3115; classtype:web-application-attack; sid:2005670; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09,
Suricata
ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-0224 [HIGH] ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname DELETE
ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname DELETE"; flow:established,to_server; http.uri; content:"/shopgiftregsearch.asp?"; nocase; content:"LoginLastname="; nocase; content:"DELETE"; nocase; pcre:"/DELETE.+FROM/i"; reference:cve,CVE-2007-0224; reference:url,www.milw0rm.com/exploits/3115; classtype:web-application-attack; sid:2005672; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic
Suricata
ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-0224 [HIGH] ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname ASCII
ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname ASCII"; flow:established,to_server; http.uri; content:"/shopgiftregsearch.asp?"; nocase; content:"LoginLastname="; nocase; content:"SELECT"; nocase; pcre:"/ASCII\(.+SELECT/i"; reference:cve,CVE-2007-0224; reference:url,www.milw0rm.com/exploits/3115; classtype:web-application-attack; sid:2005673; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tacti
Suricata
ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-0224 [HIGH] ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname UPDATE
ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname UPDATE"; flow:established,to_server; http.uri; content:"/shopgiftregsearch.asp?"; nocase; content:"LoginLastname="; nocase; content:"UPDATE"; nocase; pcre:"/UPDATE.+SET/i"; reference:cve,CVE-2007-0224; reference:url,www.milw0rm.com/exploits/3115; classtype:web-application-attack; sid:2005674; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_
Suricata
ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0224 [HIGH] ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname INSERT
ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS VP-ASP Shopping Cart SQL Injection Attempt -- shopgiftregsearch.asp LoginLastname INSERT"; flow:established,to_server; http.uri; content:"/shopgiftregsearch.asp?"; nocase; content:"LoginLastname="; nocase; content:"INSERT"; nocase; pcre:"/INSERT.+INTO/i"; reference:cve,CVE-2007-0224; reference:url,www.milw0rm.com/exploits/3115; classtype:web-application-attack; sid:2005671; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic
No public exploits indexed.
Bugzilla
CVE-2010-3113 CVE-2010-1814 CVE-2010-1812 CVE-2010-1815 CVE-2010-3115 CVE-2010-1807 CVE-2010-3114 CVE-2010-3116 CVE-2010-3257 CVE-2010-3259 webkitgtk various flaws [fedora-all]
bugzilla·2010-10-05·CVSS 9.3
CVE-2010-3113 [CRITICAL] CVE-2010-3113 CVE-2010-1814 CVE-2010-1812 CVE-2010-1815 CVE-2010-3115 CVE-2010-1807 CVE-2010-3114 CVE-2010-3116 CVE-2010-3257 CVE-2010-3259 webkitgtk various flaws [fedora-all]
CVE-2010-3113 CVE-2010-1814 CVE-2010-1812 CVE-2010-1815 CVE-2010-3115 CVE-2010-1807 CVE-2010-3114 CVE-2010-3116 CVE-2010-3257 CVE-2010-3259 webkitgtk various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://adm
Bugzilla
CVE-2010-3115 webkit: address bar spoofing with history bug
bugzilla·2010-08-27·CVSS 5.0
CVE-2010-3115 [MEDIUM] CVE-2010-3115 webkit: address bar spoofing with history bug
CVE-2010-3115 webkit: address bar spoofing with history bug
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-3115 to
the following vulnerability:
Name: CVE-2010-3115
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3115
Assigned: 20100824
Reference: CONFIRM: http://code.google.com/p/chromium/issues/detail?id=49964
Reference: CONFIRM: http://googlechromereleases.blogspot.com/2010/08/stable-channel-update_19.html
Google Chrome before 5.0.375.127 does not properly implement the
history feature, which might allow remote attackers to spoof the
address bar via unspecified vectors.
This flaw also affects upstream WebKit:
https://bugs.webkit.org/show_bug.cgi?id=42858
http://trac.webkit.org/changeset/64077
Discussion:
This issue has been corrected in WebKitGTK
http://code.google.com/p/chromium/issues/detail?id=49964http://googlechromereleases.blogspot.com/2010/08/stable-channel-update_19.htmlhttp://secunia.com/advisories/41856http://secunia.com/advisories/43086http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.redhat.com/support/errata/RHSA-2011-0177.htmlhttp://www.securityfocus.com/bid/44203http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0216http://www.vupen.com/english/advisories/2011/0552https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11953http://code.google.com/p/chromium/issues/detail?id=49964http://googlechromereleases.blogspot.com/2010/08/stable-channel-update_19.htmlhttp://secunia.com/advisories/41856http://secunia.com/advisories/43086http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.redhat.com/support/errata/RHSA-2011-0177.htmlhttp://www.securityfocus.com/bid/44203http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0216http://www.vupen.com/english/advisories/2011/0552https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11953
2010-08-24
Published