Mozilla Foundation Security Advisory 2007-24
Unauthorized access to wyciwyg:// documents
- Announced
- July 17, 2007
- Reporter
- Michal Zalewski
- Impact
- High
- Products
- Firefox, SeaMonkey
- Fixed in
-
- Firefox 2.0.0.5
- SeaMonkey 1.1.3
Description
Michal Zalewski reported that it was possible to bypass the same-origin checks and read from cached (wyciwyg) documents. It is possible to access wyciwyg:// documents without proper same domain policy checks through the use of HTTP 302 redirects. This enables the attacker to steal sensitive data displayed on dynamically generated pages; perform cache poisoning; and execute own code or display own content with URL bar and SSL certificate data of the attacked page (URL spoofing++).