Closed Bug 576875 Opened 16 years ago Closed 15 years ago

Possible Location bar Spoofing using location.reload on the <body>

Categories

(Core :: General, defect)

x86
Windows 7
defect
Not set
normal

Tracking

()

RESOLVED WORKSFORME

People

(Reporter: jordi.chancel, Unassigned)

Details

(Whiteboard: [sg:needinfo])

Attachments

(1 file)

User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; fr; rv:1.9.2.7) Gecko/20100701 Firefox/3.6.7 Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 6.1; fr; rv:1.9.2.7) Gecko/20100701 Firefox/3.6.7 When you are on an web-adress and load a 2nd adresse that contains location.reload() on the <body> , they change the document.location and steal the content of previous web page Example : <html> <body onload="location.reload();"> </body> </html> Reproducible: Sometimes Steps to Reproduce: 1.enter a first address 2.enter a second address with location.reload on the body Actual Results: the location bar is spoofed Vulnerability found by Jordi Chancel & 599eme Man
I'm not sure I follow. location.reload on a page will .... reload that page. What's the issue?
Attached file TESTCASE1
TestCase 1
Can you give more precise steps to reproduce, and describe the incorrect result we should be looking for? I didn't see anything obviously wrong when I clicked the link in the testcase.
Whiteboard: [sg:needinfo]
I think we all agree we don't see anything wrong with your testcase.
Status: UNCONFIRMED → RESOLVED
Closed: 15 years ago
Resolution: --- → WORKSFORME
Group: core-security → core-security-release
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: