MEDIUM
Mozilla Firefox allows for cookies to be set with a null domain (aka "domainless cookies"), which allows remote attackers to pass information between arbitrary domains and track user activity, as demonstrated by the domain attribute in the document.cookie variable in a javascript: window
Published Jul 17, 2007
5.0
MEDIUMCVSS 2.0
EPSS 0.93%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.