Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Konqueror: URL address bar spoofingvulnerabilities Aug 06 2007 10:37PM
Jonathan Smith (smithj rpath com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Robert Swiecki wrote:
> The second one is based on the http URI scheme which allows embedding
> user/password parameters into it, i.e. http://user:password (at) domain (dot) com. [email concealed]
> Such parameters can contain whitespaces, so the attack vector is quite
> obvious.
...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus