CVE-2014-1887 Information
Feb 14, 2021
cve
Description
The DrinkedIn BarFinder application for Android when Adobe PhoneGap 2.9.0 or earlier is used allows remote attackers to execute arbitrary JavaScript code and consequently obtain sensitive fine-geolocation information by leveraging control over one of a number of adult sites as demonstrated by (1) freelifetimecheating.com and (2) www.babesroulette.com.
Reference
http://openwall.com/lists/oss-security/2014/02/07/9 http://www.cs.utexas.edu/~shmat/shmat_ndss14nofrak.pdf http://www.internetsociety.org/ndss2014/programmesession3
Share on: