Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Mozilla/Firefox Browsers URI Drag And Drop Cross-Domain Scripting Vulnerability

Both Mozilla and Firefox are reported to be prone to a cross-domain scripting vulnerability. It is reported that URI links that are dragged from one browser window and dropped into another browser window will bypass the browser same-origin policy security checks.

Certain URI types may be employed by a malicious website in order to trigger this vulnerability. If successful, this attack will result in the execution of arbitrary script code in the context of a target domain.







 

Privacy Statement
Copyright 2008, SecurityFocus