Back

MEDIUM

webkit: stylesheet URL property leaks redirection target

Published Feb 18, 2010

Description

Mozilla Firefox, possibly before 3.6, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value, related to an IFRAME element.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 18, 2010
Updated Aug 7, 2024
Reserved Feb 18, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Jan 9, 2010