Upstream information
Description
Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having moderate severity.
National Vulnerability Database | |
---|---|
Base Score | 5 |
Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Access Vector | Network |
Access Complexity | Low |
Authentication | None |
Confidentiality Impact | Partial |
Integrity Impact | None |
Availability Impact | None |
SUSE Security Advisories:
- SUSE-SA:2005:045, published Thu, 11 Aug 2005 15:00:00 +0000
- SUSE-SA:2006:022, published Tue, 25 Apr 2006 15:00:00 +0000
SUSE Timeline for this CVE
CVE page created: Fri Jun 28 01:37:48 2013CVE page last modified: Fri Dec 8 16:12:56 2023