Bug 474967 (CVE-2009-0253)

Firefox Displays Invalid Link On Mouse-Over Hyperlink

RESOLVED WONTFIX

Status

()

Firefox
General
--
critical
RESOLVED WONTFIX
9 years ago
8 years ago

People

(Reporter: reelix, Unassigned)

Tracking

Firefox Tracking Flags

(Not tracked)

Details

(URL)

Attachments

(1 attachment)

(Reporter)

Description

9 years ago
User-Agent:       Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5 (.NET CLR 3.5.30729)
Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5 (.NET CLR 3.5.30729)

Firefox displays the incorrect location that the hyperlink is going to.

It displays http://www.google.com/ but directs you to http://www.youtube.com/

Reproducible: Always

Steps to Reproduce:
1. Open The Page

2. Mouse Over The Link (Noticing The Destination)

3. Click The Link
Actual Results:  
You are sent to http://www.youtube.com/

Expected Results:  
You should be sent to http://www.google.com/
(Reporter)

Comment 1

9 years ago
Created attachment 358370 [details]
Example Glitched Page

Comment 2

9 years ago
Not security sensitive. There are many ways that pages can achieve the same effect, such as:

<a href="http://www.google.com/" onclick="location.href='http://www.youtube.com'; return false;">link</a>
Group: core-security
Status: UNCONFIRMED → RESOLVED
Last Resolved: 9 years ago
Resolution: --- → WONTFIX
Duplicate of this bug: 475250
Duplicate of this bug: 475249
Duplicate of this bug: 513808
http://www.exploit-db.com/exploits/7842
http://milw0rm.com/exploits/7842
Alias: CVE-2009-0253
You need to log in before you can comment on or make changes to this bug.