Netscape Navigator False URL Information Vulnerability
BID:7564
Info
Netscape Navigator False URL Information Vulnerability
| Bugtraq ID: | 7564 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 13 2003 12:00AM |
| Updated: | May 13 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to Liu Die Yu <[email protected]>. |
| Vulnerable: |
Netscape Navigator 7.0.2 |
| Not Vulnerable: | |
Discussion
Netscape Navigator False URL Information Vulnerability
An issue has been reported for Netscape Navigator that may result in a false sense of security for a user. Due to the way Netscape handles the history.back() function, the URL displayed on the 'location bar' will not correspond to the actual URL of the site displayed in the browser window.
An issue has been reported for Netscape Navigator that may result in a false sense of security for a user. Due to the way Netscape handles the history.back() function, the URL displayed on the 'location bar' will not correspond to the actual URL of the site displayed in the browser window.
Exploit / POC
Netscape Navigator False URL Information Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Netscape Navigator False URL Information Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Netscape Navigator False URL Information Vulnerability
References:
References:
- Netscape Homepage (Netscape)
- fake location bar (Liu Die Yu
)