First published: Fri Apr 11 2003(Updated: )
The Google toolbar 1.1.58 and earlier allows remote web sites to monitor a user's input into the toolbar via an "onkeydown" event handler.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Toolbar | =1.1.41 | |
Google Toolbar | =1.1.58 | |
Google Toolbar | =1.1.44 | |
Google Toolbar | =1.1.42 | |
Google Toolbar | =1.1.49 | |
Google Toolbar | =1.1.55 | |
Google Toolbar | =1.1.48 | |
Google Toolbar | =1.1.57 | |
Google Toolbar | =1.1.47 | |
Google Toolbar | =1.1.43 | |
Google Toolbar | =1.1.54 | |
Google Toolbar | =1.1.53 | |
Google Toolbar | =1.1.56 | |
Google Toolbar | =1.1.45 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1443 has been classified as a medium severity vulnerability due to its potential to expose user inputs to malicious web pages.
To fix CVE-2002-1443, users should upgrade to a later version of the Google toolbar that addresses this vulnerability.
CVE-2002-1443 allows attackers to monitor user input through the Google toolbar using an onkeydown event handler.
Google toolbar versions 1.1.41 to 1.1.58 are affected by CVE-2002-1443.
Yes, user data may be at risk since CVE-2002-1443 allows remote sites to capture keystrokes entered in the Google toolbar.