>> Konqueror "setInterval()" Function Handling Address Bar Spoofing Weakness
Title : Konqueror "setInterval()" Function Handling Address Bar Spoofing Weakness VUPEN ID : VUPEN/ADV-2007-2807 CVE ID : CVE-2007-4224 - CVE-2007-4225
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-08-08
Technical Description
A weakness has been identified in Konqueror, which could be exploited by malicious websites to conduct spoofing or phishing attacks. This issue is caused by an error when handling setInterval()" calls, which could be exploited by attackers to spoof the displayed address bar by tricking a user into visiting a malicious web site or clicking on a specially crafted link.