CVE-2014-1887
Last modified
CVE-2014-1887 is a vulnerability of currently unknown severity. The DrinkedIn BarFinder application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently obtain sensitive fine-geolocation information, by leveraging control over one of a number of adult sites, as demonstrated by (1) freelifetimecheating.com and (2) www.babesroulette.com.. EPSS estimates a 1.34% chance of exploitation in the next 30 days.
Description
The DrinkedIn BarFinder application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently obtain sensitive fine-geolocation information, by leveraging control over one of a number of adult sites, as demonstrated by (1) freelifetimecheating.com and (2) www.babesroulette.com.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Drinkedin | Drinkedin Barfinder | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-1887?
How severe is CVE-2014-1887?
How do I fix CVE-2014-1887?
Are you affected by CVE-2014-1887?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
