CVE-2007-1256 Information

Description

Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar favicons and document source and perform updates in the context of arbitrary websites by repeatedly setting document.location in the onunload attribute when linking to another website a variant of CVE-2007-1092.

Reference

http://marc.info/?l=full-disclosure&m=117258301222007&w=2 http://marc.info/?l=full-disclosure&m=117259225402112&w=2 http://osvdb.org/35913 http://www.securityfocus.com/archive/1/461437/100/0/threaded

Share on: