BetaONE will rise again!


Reply
  #1  
Old 9th Nov 07, 08:26 PM
NewsBot's Avatar
NewsBot NewsBot is offline
Senior Member
 
Join Date: Oct 2004
Posts: 31,337
NewsBot will become famous soon enough
"JAR:" protocol vulnerability discovered in Firefox
A vulnerability, which could be exploited to conduct cross site scripting attacks and gain knowledge of sensitive information, has been identified in Mozilla Firefox 2.0.0.9,. This issue is caused by an input and origin validation error in the implementation of the "jar" protocol, which could be exploited by attackers to cause malicious scripting code to be executed by a user's browser in the security context of an arbitrary Web site by tricking the user into following a specially crafted link. The vulnerability is due to same origin and XSS issues when opening .JAR packages. The following file formats are known attack vectors: .zip, .doc, and .odt.

News source: Gnucitizen

Read full story...



More...
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Neowin Member Interview: Asa Dotzler - Firefox Developer NewsBot NeoWin News 0 20th Jul 05 09:30 PM
Firefox javascript vulnerability discovered NewsBot ieXbeta News 0 5th Apr 05 03:00 PM
Firefox breaks 25 million downloads in less than 100 days NewsBot NeoWin News 0 18th Feb 05 07:30 AM
Firefox: The Road Ahead NewsBot NeoWin News 0 15th Jan 05 02:00 AM
Massive vulnerability discovered in phpBB NewsBot ieXbeta News 0 24th Dec 04 06:00 AM


All times are GMT +1. The time now is 10:06 PM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.