Thursday, June 14, 2007

Apple Safari 3.0.1: URLbar / Window Title Spoofing

Posted by Robert Swiecki on June 14th to the bugtraq & FD mailing list -

Here's another one.

With a specially crafted web page, an attacker can fill the client browser window with an arbitrary content, whereas window title and the content of the urlbar are freely settable.

Tested with shiny, new, patched Safari 3.0.1 (522.12.12) on Windows 2003 SE SP2.

http://alt.swiecki.net/saff.html [PoC]

No comments:

Post a Comment