BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: [Full-disclosure] Firefox: serious cookie stealing / same-domain bypass vulnerability Feb 15 2007 03:17PM
pdp (architect) (pdp gnucitizen googlemail com)
the first one runs in about:blank which is restricted. the second one
is very interesting but still not very useful because it acts like
about:blank. hmmm it seams that the hostname field has been seriously
overlooked.

On 2/15/07, Michal Zalewski <lcamtuf (at) dione.ids (dot) pl [email concealed]> wrote:
> On Thu, 15 Feb 2007,...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus