Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: [Full-Disclosure] Fireflashing [Firefox 1.0] Feb 12 2005 02:25PM
Jelmer Kuperus (jkuperus planet nl)
I took a quick 5 minute look at this, and it looks like you can read
arbitrary files with this without requiring any kind of user interaction.

Just create a file called whatever.html on a windows SMB share with this
content

--snip--

<script language="javascript">
var oXML=new XMLHttpRequest...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus