Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-5960 (Firefox, SeaMonkey)

BugsAlert Home > CVE-2007-5960 (Firefox, SeaMonkey)
 
 

Mozilla Firefox before 2.0.0.10 and SeaMonkey 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer headers and bypass Referer-based CSRF protection schemes by setting window.location and using a modal alert dialog that causes the wrong Referer to be sent.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5960

Learn more about CVE-2007-5960 (Firefox, SeaMonkey)
 
Tags: cve-2007-5960 firefox seamonkey

Related Items

      CVE-2007-6029 (ClamAV)

      President Sarkozy's bank account hacked

      CVE-2008-3786 (PicturesPro Photo Cart)

      Ubuntu: Linux kernel vulnerabilities

      WORM_GAMMIMA.H

      CVE-2008-3195 (twiki)

      Watch Out for Hurricane Gustav Relief Scams

 

Pixel