Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Google Chrome before 1.0.154.46 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls and other web script.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
google chrome 权限许可和访问控制漏洞
Vulnerability Description
Google Chrome是Google发布的一款浏览器。 Google Chrome 1.0.154.46之前的版本没有正确的限制来自web页对(1)Set-Cookie和(2)Set-Cookie2 HTTP响应头的访问,这使得远程攻击者可以借助XMLHttpRequest呼叫和其他web脚本,从cookies中获得敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A