Pré-requisitos
Victim's browser visits a website that contains attacker's Java ScriptJava Script is not disabled in the victim's browser
Mitigações
Configuration: Disable Java Script in the browser
Fraquezas Relacionadas
| CWE-ID |
Nome da Fraqueza |
|
Exposure of Sensitive Information to an Unauthorized Actor The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Referências
REF-410
Detecting browsers javascript hacks
Gareth Heyes.
http://www.thespanner.co.uk/2009/01/29/detecting-browsers-javascript-hacks/
Submissão
| Nome |
Organização |
Data |
Data de lançamento |
| CAPEC Content Team |
The MITRE Corporation |
2014-06-23 +00:00 |
|
Modificações
| Nome |
Organização |
Data |
Comentário |
| CAPEC Content Team |
The MITRE Corporation |
2022-09-29 +00:00 |
Updated Example_Instances |