![]() | |
| |||||||
| Home | Register | Projects | Blogs | FAQ | Calendar | Search | Today's Posts | Mark Forums Read | Free Directory | Free DNSReport | Tags |
| Notices |
| Advisories Discuss about all newly security flaws classed by CVE entries and reviewed by security experts |
CVE-2007-6589 (Firefox, SeaMonkey)This is a discussion on "CVE-2007-6589 (Firefox, SeaMonkey)" within the Advisories part of the Computer Security: Discussions section; The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 does not update the origin domain when retrieving the inner URL parameter yields an HTTP redirect, which allows remote attackers to conduct ... |
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 does not update the origin domain when retrieving the inner URL parameter yields an HTTP redirect, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI, a different vulnerability than CVE-2007-5947. More... |
| Sponsor | ||
| ||
| |
![]() |
| | |
| cve20076589, firefox, seamonkey | |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| CVE-2008-0592 (Firefox, SeaMonkey) | Heap | Advisories | 0 | 11-02-08 17:29 |
| CVE-2007-6590 (Firefox, Mozilla, SeaMonkey, Netscape) | Heap | Advisories | 0 | 31-12-07 05:53 |
| CVE-2007-5960 (Firefox, SeaMonkey) | Heap | Advisories | 0 | 28-11-07 04:26 |
| CVE-2007-5959 (Firefox, SeaMonkey) | Heap | Advisories | 0 | 28-11-07 04:26 |
| CVE-2007-5339 (Firefox, Thunderbird, SeaMonkey) | Heap | Advisories | 0 | 25-10-07 03:08 |