Apple Safari: cookie stealing

看板Bugtraq作者時間18年前 (2007/06/13 21:47), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
There is a vulnerability in Apple Safari, that allows an attacker to steal a cookie belonging to the arbitrary domain or/and fill the browser window with an arbitrary content, whereas the url bar and the browser's window title is derived from the selected domain. The flaw exists in the javascript's window.setTimeout() implementation. The content of the timer-triggered function is processed after window.location property is changed. Tested with Apple Safari 3.0 (522.11.3) on MS Windows 2003 SE SP2 http://alt.swiecki.net/safc.html -- Robert Swiecki http://www.swiecki.net
文章代碼(AID): #16R_Lt00 (Bugtraq)