Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Mozilla/Firefox Browsers PrivilegeManager EnablePrivilege Dialog Manipulation Vulnerability

A vulnerability is reported in the Mozilla 'enablePrivilege' method. Because the argument data of a 'enablePrivilege' method is used as text in a prompt dialog if the user has not accessed the principal previously, it is possible to manipulate dialog contents.

A remote attacker may exploit this condition to influence a victim user into permitting a malicious script to run.







 

Privacy Statement
Copyright 2008, SecurityFocus