News
[PSUs]| Tuesday 21st June 2005 |
Fresh spoofing vulnerability found in browsers
12:56PM, Tuesday 21st June 2005
A dialog origin spoofing vulnerability has been discovered in several Web browsers, including the leading browsers for both Mac OS X and Windows.
The vulnerability, rated less critical, affects Safari, Internet Explorer 5.x, Camino 0.x and iCab 2.x for OS X; IE 6.x for Windows; and Opera 7.x and 8.x, Mozilla 1.7x and all version of Firefox on both platforms.
The problem, identified by Secunia, is that JavaScript dialog boxes do not display or include their origin, which allows a new window to open a dialog box, which appears to be from a trusted site. Successful exploitation normally requires that a user is tricked into opening a link from a malicious website to a trusted website.
More information can be found at secunia.com/advisories.
Submit to: Digg | Slashdot | Del.icio.us | Technorati






