CVE-2015-6784
06.12.2015, 01:59
The page serializer in Google Chrome before 47.0.2526.73 mishandles Mark of the Web (MOTW) comments for URLs containing a "--" sequence, which might allow remote attackers to inject HTML via a crafted URL, as demonstrated by an initial http://example.com?-- substring.Enginsight
Vendor | Product | Version |
---|---|---|
chrome | 𝑥 ≤ 46.0.2490.86 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||
---|---|---|---|---|---|---|---|---|---|
chromium-browser |
| ||||||||
oxide-qt |
|
Common Weakness Enumeration
References