Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Firefox + popup blocker + XMLHttpRequest + srand() = oops Feb 05 2007 12:18PM
Michal Zalewski (lcamtuf dione ids pl)
There is an interesting vulnerability in the default behavior of Firefox
builtin popup blocker. This vulnerability, coupled with an additional
trick, allows the attacker to read arbitrary user-accessible files on the
system, and thus steal some fairly sensitive information.

This was tested on 1.5.0...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus