Mark / IL

Rapid Fingerpointing Machinery

Mark / IL header image 2

Path Traversal via DOM Injection Vulnerability in Firefox 2.0.0.12

February 9th, 2008 · 8 Comments

If you're new here, you may want to subscribe to my RSS feed. Thanks for visiting!

This is obviously no longer an issue. Please see the comments for more information.

As posted on 0×00000, Mozilla Firefox 2.0.0.12 is vulnerable by default to a directory traversal trick, via the view-source mechanism. Although mitigated by the NoScript plug-in, this is quite a serious bug — the default installation is vulnerable from the get-go.

After a slew of point releases and similar vulnerabilities, this comes rather surprisingly — the Firefox team are usually rather thorough in their bug cleansing; hopefully, this will be fixed as promptly as usual.

POC code mirror.

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Netvouz
  • DZone
  • ThisNext
  • MisterWong
  • Wists
  • Fark
  • Furl
  • StumbleUpon
  • Taggly
  • YahooMyWeb

Tags: Technology

8 responses so far ↓

Leave a Comment