CVE-2004-2475: XSS
Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protocol does not cross privilege boundaries, since it is not allowed in the Internet Zone. Thus this might not be a vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2475?
CVE-2004-2475 is classified as a high severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2004-2475?
To address CVE-2004-2475, users should upgrade to a non-vulnerable version of Google Toolbar, as specific patches are not provided.
What impact does CVE-2004-2475 have on users?
CVE-2004-2475 can allow remote attackers to inject arbitrary web scripts, potentially leading to session hijacking or information theft.
Which versions of Google Toolbar are affected by CVE-2004-2475?
CVE-2004-2475 affects Google Toolbar versions 1.1.41 through 2.0.114.1.
Can CVE-2004-2475 be exploited using a specific method?
Yes, CVE-2004-2475 can be exploited by injecting scripts via the about.html page in the About section of Google Toolbar.