Closed
Bug 593599
Opened 14 years ago
Closed 14 years ago
XSS using javascript URL
Categories
(Core :: Security, defect)
Tracking
()
People
(Reporter: moz_bug_r_a4, Assigned: mrbkap)
Details
(Whiteboard: [sg:high][fixed by 576616])
Bug 576616 comment #13
> moz_bug_r_a4: I'm assuming the location object is the only thing affected, but
> the patch looks generic. Maybe you can turn this into more damage.
It's possible to perform an XSS attack by using the bug that the patch fixes.
Reporter | ||
Comment 1•14 years ago
|
||
This uses bug 344495's trick.
This tries to get cookies for www.mozilla.com.
This works on 1.9.2 and 1.9.1 (and fx-4.0b3pre-2010-07-22-08).
Updated•14 years ago
|
Assignee: nobody → mrbkap
blocking1.9.1: --- → ?
blocking1.9.2: --- → ?
status1.9.1:
--- → wanted
status1.9.2:
--- → wanted
Depends on: CVE-2010-3178
Whiteboard: [sg:high] fixed by 576616 on trunk
Updated•14 years ago
|
blocking1.9.1: ? → .13+
blocking1.9.2: ? → .10+
Updated•14 years ago
|
Whiteboard: [sg:high] fixed by 576616 on trunk → [sg:high][1.9.2 and older: fixed by 576616 on trunk]
sg:high -> punt to next version.
blocking1.9.1: .14+ → needed
blocking1.9.2: .11+ → needed
Updated•14 years ago
|
Whiteboard: [sg:high][1.9.2 and older: fixed by 576616 on trunk] → [sg:high][fixed by 576616]
Updated•14 years ago
|
Attachment #472164 -
Attachment is private: true
Assignee | ||
Comment 3•14 years ago
|
||
This is fixed on trunk by the patch for bug 576616.
Status: NEW → RESOLVED
Closed: 14 years ago
Resolution: --- → FIXED
Updated•14 years ago
|
Depends on: CVE-2010-3178
Updated•14 years ago
|
Depends on: CVE-2010-3178
Updated•14 years ago
|
Group: core-security
No longer depends on: CVE-2010-3178, CVE-2010-3178
You need to log in
before you can comment on or make changes to this bug.
Description
•