CVE-2014-1883
Published Mar 3, 2014
Last updated 11 years ago
Overview
- Description
- Adobe PhoneGap before 2.6.0 on Android uses the shouldOverrideUrlLoading callback instead of the proper shouldInterceptRequest callback, which allows remote attackers to bypass intended device-resource restrictions via content that is accessed (1) in an IFRAME element or (2) with the XMLHttpRequest method by a crafted application.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:adobe:phonegap:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "93E78BA0-EE60-4C8F-B92A-2A69D8DD43A1", "versionEndIncluding": "2.5.0" }, { "criteria": "cpe:2.3:a:adobe:phonegap:2.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D3B05BE6-D8DA-40C8-BA86-67B1FD906975" }, { "criteria": "cpe:2.3:a:adobe:phonegap:2.0.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C57DD500-22A7-4209-AEF7-DC8930F1BDD9" }, { "criteria": "cpe:2.3:a:adobe:phonegap:2.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "16EC33AF-5D22-418D-8604-EB549A197209" }, { "criteria": "cpe:2.3:a:adobe:phonegap:2.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6C8124E0-6A2F-493E-875E-1D0E613A366B" }, { "criteria": "cpe:2.3:a:adobe:phonegap:2.2.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D6D5BDFF-A635-45D6-A346-754BFACD00A6" }, { "criteria": "cpe:2.3:a:adobe:phonegap:2.2.0:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0A0B3637-4927-47AD-87A0-EE411C12EE06" }, { "criteria": "cpe:2.3:a:adobe:phonegap:2.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B6451A3E-BEB0-4EE0-AD88-8CE3E048CB10" }, { "criteria": "cpe:2.3:a:adobe:phonegap:2.3.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EBEEDD73-74C5-4299-8509-324A829623D8" }, { "criteria": "cpe:2.3:a:adobe:phonegap:2.3.0:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0BC85762-A07D-4C44-8458-08FC2F717462" }, { "criteria": "cpe:2.3:a:adobe:phonegap:2.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9C19E85E-6E96-4F24-8A10-393B9DB1770F" }, { "criteria": "cpe:2.3:a:adobe:phonegap:2.4.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CA489695-A354-4921-903F-65AD650BCB61" }, { "criteria": "cpe:2.3:a:adobe:phonegap:2.5.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4C20AC3F-8A9D-4450-AB38-2FC4A19605F9" } ], "operator": "OR" } ] } ]