Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Firefox wyciwyg:// cache zone bypass Jul 09 2007 01:37PM
Michal Zalewski (lcamtuf dione ids pl)
There is an interesting vulnerability in how Mozilla Firefox handles
internal wyciwyg:// pseudo-URIs. These cache-related resource identifiers
are meant to be inaccessible by the user - but there are at least three
routes to bypass these restrictionss, one of which - HTTP 302 redirect -
also imprope...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus