# Google Chrome 4.1.249.1059 Cross Origin Bypass in Google URL (GURL) # # CVE-ID: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1663 # # Author: Jordi Chancel # # Software Link: http://googlechromereleases.blogspot.com/2010/04/stable-update-bug-and-security-fixes.html # # Description: { # The Google URL Parsing Library (aka google-url or GURL) in Google Chrome # before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy # via CHARACTER TABULATION or others escape characters inside javascript: protocol string. } # # Some PoC : Inject JavaScript ---- Inject JavaScript ---- Inject JavaScript ---- Inject JavaScript ---- Inject JavaScript Greetz : Xylitol , Eddy Bordi , 599eme Man , Gnouf , CTZ .