Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2004-0191
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-0191

Description:
Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.

CVE Status:
Entry

References:

XF

REDHAT

OVAL

OSVDB
  4062

HP

CONFIRM
  http://bugzilla.mozilla.org/show_bug.cgi?id=227417

BUGTRAQ

BID
  9747


Return to the previous page.