Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: [Full-disclosure] Firefox: serious cookie stealing / same-domain bypass vulnerability Feb 15 2007 02:58PM
Michal Zalewski (lcamtuf dione ids pl)
On Thu, 15 Feb 2007, pdp (architect) wrote:

> I wander whether we can execute code on about:config or about:cache.

Actually, there are several odd problems related to location updates and
location.hostname specifically, including one scenario that apparently
makes the script run with document.loca...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus