Closed Bug 1284470 Opened 10 years ago Closed 10 years ago

Local Cross-site Scripting Vulnerability found in mozilla browser version 47.0

Categories

(Core :: Security, defect)

47 Branch
x86_64
Linux
defect
Not set
normal

Tracking

()

RESOLVED INVALID

People

(Reporter: vaishnavgeet183, Unassigned)

Details

(Keywords: reporter-external, Whiteboard: [reporter-external] [web-bounty-form] [verif?])

Attachments

(1 file)

Step to reproduce: Step A - Follow the step shown in "http://www.securityfocus.com/archive/1/537275/30/0/threaded" (payload) - <script>;prompt(0)</script> Step B - Encode the payload using base64. (Encoded payload) - PHNjcmlwdD47cHJvbXB0KDApPC9zY3JpcHQ+ Step C - Open you browser and then put above encoded payload with - data:text/html;base64,{encoded Payload} data:text/html;base64,PHNjcmlwdD47cHJvbXB0KDApPC9zY3JpcHQ+ Step D - Now hit enter and you will see pop-up.
Flags: sec-bounty?
Group: websites-security → core-security
Component: Other → Security
OS: All → Linux
Product: Websites → Core
Hardware: All → x86_64
Version: unspecified → 46 Branch
Version: 46 Branch → 47 Branch
This has been reported to us before, as the thread you link to mentions, and is an invalid issue.
Status: UNCONFIRMED → RESOLVED
Closed: 10 years ago
Resolution: --- → INVALID
Group: core-security
Flags: sec-bounty? → sec-bounty-
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: