4.3
CVSSv2

CVE-2010-4804

Published: 09/06/2011 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 436
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Android browser in Android prior to 2.3.4 allows remote malicious users to obtain SD card contents via crafted content:// URIs, related to (1) BrowserActivity.java and (2) BrowserSettings.java in com/android/browser/.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google android 1.6

google android 2.1

google android 2.3

google android 1.5

google android 2.2.1

google android 2.2.2

google android 2.2

google android

Exploits

<?php /* * Description: Android 'content://' URI Multiple Information Disclosure Vulnerabilities * Bugtraq ID: 48256 * CVE: CVE-2010-4804 * Affected: Android < 234 * Author: Thomas Cannon * Discovered: 18-Nov-2010 * Advisory: thomascannonnet/blog/2010/11/android-data-stealing-vulnerability/ * * Filename ...
Android versions prior to 234 suffer from content:// URI information disclosure vulnerabilities ...

Github Repositories

Android Data Stealing Vulnerability

Proof of Concept for Android Data Stealing Vulnerability CVE-2010-4804 Original advisory

A curated list of my GitHub stars!

Awesome Stars A curated list of my GitHub stars! Generated by starred Contents Assembly AutoHotkey AutoIt Batchfile BitBake C C# C++ CSS Clojure CoffeeScript Common Lisp Dart Genshi Go Gosu Groovy HTML Haskell Inno Setup Java JavaScript Jupyter Notebook Kotlin Lua Makefile Markdown NSIS Objective-C Others PHP Pascal Perl PowerShell Python R Roff Ruby Rust SCSS Scala Shell