Mozilla Firefox 'MakeScriptDialogTitle()' URI Spoofing Vulnerability
BID:37232
Info
Mozilla Firefox 'MakeScriptDialogTitle()' URI Spoofing Vulnerability
| Bugtraq ID: | 37232 |
| Class: | Design Error |
| CVE: |
CVE-2009-4130 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 07 2009 12:00AM |
| Updated: | Dec 08 2009 12:14AM |
| Credit: | Topsec |
| Vulnerable: |
Mozilla Firefox 3.5.5 Mozilla Firefox 3.5.4 Mozilla Firefox 3.5.3 Mozilla Firefox 3.5.2 Mozilla Firefox 3.5.1 Mozilla Firefox 3.5 Mozilla Firefox 3.0.15 Mozilla Firefox 3.0.14 Mozilla Firefox 3.0.13 Mozilla Firefox 3.0.12 Mozilla Firefox 3.0.11 Mozilla Firefox 3.0.10 Mozilla Firefox 3.0.9 Mozilla Firefox 3.0.8 Mozilla Firefox 3.0.7 Beta Mozilla Firefox 3.0.7 Mozilla Firefox 3.0.6 Mozilla Firefox 3.0.5 Mozilla Firefox 3.0.4 Mozilla Firefox 3.0.3 Mozilla Firefox 3.0.2 Mozilla Firefox 3.0.1 Mozilla Firefox 3.1 Beta 3 Mozilla Firefox 3.1 Beta 2 Mozilla Firefox 3.1 Beta 1 Mozilla Firefox 3.0 Beta 5 Mozilla Firefox 3.0 |
| Not Vulnerable: | |
Discussion
Mozilla Firefox 'MakeScriptDialogTitle()' URI Spoofing Vulnerability
Mozilla Firefox is affected by a spoofing vulnerability.
An attacker may leverage this issue to present a message window with a misleading URI in the title. This may lead to a false sense of trust because the victim may be presented with a URI of a seemingly trusted site while interacting with the attacker's malicious site.
Mozilla Firefox is affected by a spoofing vulnerability.
An attacker may leverage this issue to present a message window with a misleading URI in the title. This may lead to a false sense of trust because the victim may be presented with a URI of a seemingly trusted site while interacting with the attacker's malicious site.
Exploit / POC
Mozilla Firefox 'MakeScriptDialogTitle()' URI Spoofing Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web document.
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web document.
Solution / Fix
Mozilla Firefox 'MakeScriptDialogTitle()' URI Spoofing Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Mozilla Firefox 'MakeScriptDialogTitle()' URI Spoofing Vulnerability
References:
References:
- Mozilla Homepage (Mozilla Foundation)
- Mozilla Firefox JavaScript Prompt Spoofing Weakness (tcphttp
)