7.5
CVSSv2

CVE-2014-1883

Published: 03/03/2014 Updated: 03/03/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Adobe PhoneGap prior to 2.6.0 on Android uses the shouldOverrideUrlLoading callback instead of the proper shouldInterceptRequest callback, which allows remote malicious users to bypass intended device-resource restrictions via content that is accessed (1) in an IFRAME element or (2) with the XMLHttpRequest method by a crafted application.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

adobe phonegap 2.3.0

adobe phonegap 2.4.0

adobe phonegap

adobe phonegap 2.2.0

adobe phonegap 2.0.0

adobe phonegap 2.1.0

adobe phonegap 2.5.0