Mozilla and Firefox Vulnerable to Cross Site Scripting

A vulnerability in Mozilla and Firefox browsers could allow remote intruders to bypass security restrictions and gain access to private information.

ITPro Today

February 1, 2006

1 Min Read
ITPro Today logo in a gray background | ITPro Today

A vulnerability in Mozilla and Firefox browsers could allow remote intruders to bypass security restrictions and gain access to private information. A remote intruder could cause a script to execute in the user's browser in the security context of an arbitrary domain. The problem could lead to exposure of information stored in cookies. The vulnerability is due to validation errors when processing Cascading Style Sheets (CSS) and HTML documents that contain a specially crafted property and used in conjunction with the eXtensible Binding Language (XBL). Mozilla Foundation is aware of the problem however no fix is available at this time.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like