6.8
CVSSv2

CVE-2013-6634

Published: 07/12/2013 Updated: 06/03/2014
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The OneClickSigninHelper::ShowInfoBarIfPossible function in browser/ui/sync/one_click_signin_helper.cc in Google Chrome prior to 31.0.1650.63 uses an incorrect URL during realm validation, which allows remote malicious users to conduct session fixation attacks and hijack web sessions by triggering improper sync after a 302 (aka Found) HTTP status code.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome 31.0.1650.61

google chrome 31.0.1650.60

google chrome 31.0.1650.52

google chrome 31.0.1650.51

google chrome 31.0.1650.14

google chrome 31.0.1650.15

google chrome 31.0.1650.16

google chrome 31.0.1650.23

google chrome 31.0.1650.25

google chrome 31.0.1650.31

google chrome 31.0.1650.32

google chrome 31.0.1650.39

google chrome 31.0.1650.4

google chrome 31.0.1650.41

google chrome 31.0.1650.48

google chrome 31.0.1650.49

google chrome 31.0.1650.57

google chrome 31.0.1650.55

google chrome 31.0.1650.10

google chrome 31.0.1650.11

google chrome 31.0.1650.19

google chrome 31.0.1650.2

google chrome 31.0.1650.28

google chrome 31.0.1650.29

google chrome 31.0.1650.35

google chrome 31.0.1650.36

google chrome 31.0.1650.44

google chrome 31.0.1650.45

google chrome 31.0.1650.7

google chrome 31.0.1650.8

google chrome 31.0.1650.59

google chrome 31.0.1650.58

google chrome 31.0.1650.50

google chrome 31.0.1650.0

google chrome 31.0.1650.17

google chrome 31.0.1650.18

google chrome 31.0.1650.26

google chrome 31.0.1650.27

google chrome 31.0.1650.33

google chrome 31.0.1650.34

google chrome 31.0.1650.42

google chrome 31.0.1650.43

google chrome 31.0.1650.5

google chrome 31.0.1650.6

google chrome

google chrome 31.0.1650.54

google chrome 31.0.1650.53

google chrome 31.0.1650.12

google chrome 31.0.1650.13

google chrome 31.0.1650.20

google chrome 31.0.1650.22

google chrome 31.0.1650.3

google chrome 31.0.1650.30

google chrome 31.0.1650.37

google chrome 31.0.1650.38

google chrome 31.0.1650.46

google chrome 31.0.1650.47

google chrome 31.0.1650.9