BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Disclosure of file system information in Mozilla Firefox and Opera Browser: Dec 02 2004 01:49AM
Liu Die Yu (liudieyu umbrella name)
Target user doesn't need to click the OPEN button:
1. Cross-site scripting vulnerabilities can get it done(on Mozilla, an
internet page can't navigate to a local page directly ... but there are
ways to bypass this restriction).
2. Ask target to open an HTML file in a remote SMBFS folder - expectin...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus