Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2017-20202
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Web Developer for Chrome v0.4.9 Malicious Backdoor Supply Chain Compromise
Source: NVD (National Vulnerability Database)
Vulnerability Description
Web Developer for Chrome v0.4.9 contained malicious code that generated a domain via a DGA and fetched a remote script. The fetched script conditionally loaded follow-on modules that performed extensive ad substitution and malvertising, displayed fake “repair” alerts that redirected users to affiliate programs, and attempted to harvest credentials when users logged in. Injected components enumerate common banner sizes for substitution, replace third-party ad calls, and redirect victim traffic to affiliate landing pages. Potential impacts include user-level code execution in the browser context, large-scale ad fraud and traffic hijacking, credential theft, and exposure to additional payloads delivered by the actor. The compromise was reported on by the maintainer of Web Developer for Chrome on August 2, 2017 and remediated in v0.5.0.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
内嵌的恶意代码
Source: NVD (National Vulnerability Database)
Vulnerability Title
Web Developer for Chrome 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Web Developer for Chrome是Chris Pederick个人开发者的一个浏览器开发者扩展。 Web Developer for Chrome 0.4.9版本存在安全漏洞,该漏洞源于恶意代码通过DGA生成域名并获取远程脚本,可能导致用户级代码执行、大规模广告欺诈、流量劫持和凭据窃取。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
Web Developer for ChromeWeb Developer for Chrome 0.4.9 -
II. Public POCs for CVE-2017-20202
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2017-20202
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2017-20202

No comments yet


Leave a comment