angler-fishThe Vulnerability History Project

CVE-2014-1723
aka Right to Left to Wrong

Malicious actors could insert a right to left (RtL Character) into a url using their keyboard to create very misleading urls. The RtL reverses characters after it in a string in the GUI. This character is completely insivible to the users of chromium, so it was almost impossible to detect. For example, a malicious user could use this character and create a url like "coolcamsj.png". However, due to the RtL character in the url, the browser would actually read the string as "coolcamgnp.js" and load that, which has the potential to be malicious javascript.



Personally, I think that requirement mistakes were made that led to this vulnerability. The original coders either didn't have knowledge of this character or how it could lead to problems in the future, but it eventually came up. Luckily, it was reported by a good samaritan, hopefully before any malicious users had the chance to use it against other users.

  • There are no articles here... yet

Timeline

Hover over an event to see its title.
Click on the event to learn more.
Filter by event type with the buttons below.

expand_less