[Full-disclosure] New flaw found in Firefox 2.0.0.4: Firefox file input focus vulnerabilities

Guasconi Vincent tyoptyop at gmail.com
Sun Jul 1 00:26:38 BST 2007


On 7/1/07, ascii <ascii at katamail.com> wrote:
> carl hardwick wrote:
>> PoC here: http://yathong.googlepages.com/FirefoxFocusBug.html
>> The vulnerability allows the attacker to silently redirect focus
>> [...]
>
> many thanks for sharing this : )
> it's a pretty serious vulnerability as said by Zalewski

Pretty serious for you, me, and some others.
0.02$ that it will never be patched.

-- 
Guasconi Vincent
Etudiant.
http://altmylife.blogspot.com




Full-Disclosure is hosted and sponsored by Secunia.