Release date:
Updated on: 2012-08-02
Affected Systems:
Kaspersky Labs Password Manager
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54760
Kaspersky Password Manager is a Password protection application that automates Password Input and other website input processes.
Kaspersky Password Manager 5.0.0.164 and other versions have the HTML injection vulnerability in implementation. After successful exploitation, attackers can run the HTML and script code provided by attackers in the affected browsers, steal authentication creden。 or control the appearance of the site.
<* Source: Benjamin Kunz Mejri
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Kaspersky Labs
--------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.kaspersky.com/