Rapid7 Vulnerability & Exploit Database

MFSA2005-05 Firefox: Input stealing from other tabs

Back to Search

MFSA2005-05 Firefox: Input stealing from other tabs

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
11/21/2013
Created
07/25/2018
Added
11/21/2013
Modified
11/21/2013

Description

Jakob Balle of Secunia reported two vulnerabilities in windows with multiple tabs. Malicious content in a background tab can attempt to steal information intended for the topmost tab by popping up prompt dialog that appears to come from the trusted site, or by silently redirecting input focus to a background tab hoping to catch the user inputting something sensitive.Jesse Ruderman and Martin Wargers discovered variants

Solution(s)

  • mozilla-firefox-upgrade-1_0_0

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;