Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protocol does not cross privilege boundaries, since it is not allowed in the Internet Zone. Thus this might not be a vulnerability.
2004-12-31T05:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | toolbar | 1.1.41 | Yes | |
Application | toolbar | 1.1.42 | Yes | |
Application | toolbar | 1.1.43 | Yes | |
Application | toolbar | 1.1.44 | Yes | |
Application | toolbar | 1.1.45 | Yes | |
Application | toolbar | 1.1.47 | Yes | |
Application | toolbar | 1.1.48 | Yes | |
Application | toolbar | 1.1.49 | Yes | |
Application | toolbar | 1.1.53 | Yes | |
Application | toolbar | 1.1.54 | Yes | |
Application | toolbar | 1.1.55 | Yes | |
Application | toolbar | 1.1.56 | Yes | |
Application | toolbar | 1.1.57 | Yes | |
Application | toolbar | 1.1.58 | Yes | |
Application | toolbar | 1.1.59 | Yes | |
Application | toolbar | 1.1.60 | Yes | |
Application | toolbar | 2.0.114.1 | Yes | |
Application | toolbar | 2.0.114.1 | Yes |