Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: [Full-disclosure] Firefox: serious cookie stealing / same-domain bypass vulnerability Feb 15 2007 02:31PM
pdp (architect) (pdp gnucitizen googlemail com)
very good work

I wander whether we can execute code on about:config or about:cache.
Right now we can only modify cookies and bypass the same origin
policy. If we can get JavaScript running on about:cache or
about:config or some chrome URL, we might be able to completely hijack
the browser.

If that...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus