mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-10 07:47:42 +02:00
882 B
882 B
CVE-2015-5256
Description
Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly implements a JavaScript whitelist protection mechanism, which allows attackers to bypass intended access restrictions via a crafted URI.
POC
Reference
- http://packetstormsecurity.com/files/134497/Apache-Cordova-3.7.2-Whitelist-Failure.html
- http://packetstormsecurity.com/files/134497/Apache-Cordova-3.7.2-Whitelist-Failure.html