W3M Frame Enabled Browsing Cross Site Scripting Vulnerability

A cross site scripting vulnerability has been reported for W3M if frames support is enabled. Due to inadequate sanitization of some HTML tags, it is possible for an attacker to steal another user's cookie information or other sensitive data.


 

Privacy Statement
Copyright 2010, SecurityFocus