UNSOLVED

ky331

updated

16 years ago

K

ky331

5 Journeyman

15622 Posts

45048 Points

0

1625

May 28th, 2010 05:00

Firefox Information Disclosure Vulnerability - UNpatched

The following has been copied/pasted from http://secunia.com/advisories/39925/ (dated 2010-05-27):

a ["less critical"] vulnerability [has been discovered] in Mozilla Firefox, which can be exploited by malicious people to disclose potentially sensitive information.

The vulnerability is caused due to the "window.onerror" handler being allowed to read the destination URL of a redirection. This can be exploited to e.g. disclose session-specific query parameters contained in a target URL by referencing a redirecting site via an HTML "

No Responses