>> Konqueror Browser "data:" URI Scheme Address Bar Spoofing Vulnerability
Title : Konqueror Browser "data:" URI Scheme Address Bar Spoofing Vulnerability VUPEN ID : VUPEN/ADV-2007-2538 CVE ID : CVE-2007-3820
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-07-16
Technical Description
A weakness has been identified in Konqueror, which could be exploited by malicious websites to conduct spoofing or phishing attacks. This issue is caused by an error when handling "data:" URIs, which could be exploited by attackers to spoof the displayed address bar by tricking a user into clicking on a specially crafted link.