iCab 2.9.8 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the Dialog Origin Spoofing Vulnerability.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Icab | Alexander_clauss | 2.9.8 (including) | 2.9.8 (including) |