![]() |
![]() |
![]() |
![]() |
![]() |
Information about your favorite browser: news, articles and more.
Firefox Open To New XSS Flaw
Published November 22nd, 2006 in All Categories, Exploits & Vulnerabilities, Firefox
An in-the-wild phish found on MySpace exposes unwary users to a flaw in Mozilla’s Password
Manager that allows a cross site scripting exploit to steal login information.
The report by Robert Chapin called the newly discovered problem a reverse cross-site request in describing the problem. He noted that while the attack targets Internet Explorer, the behavior of the Password Manager in Firefox "makes the attack much more likely to succeed."
Chapin submitted the report on Bugzilla, Mozilla’s bug-tracking database, where he described the problem in specific and general terms Firefox Open To New XSS Flaw








