The Firefox password manager vulnerability
Posted Nov 30, 2006 9:13 UTC (Thu) by
khim (subscriber, #9252)
In reply to:
The Firefox password manager vulnerability by mms
Parent article:
The Firefox password manager vulnerability
Previous answer was much better then your long tirada. Have you even read the article ?
The problem happens not when the wrong site shows the form. Problem happens when "trusted" site allow HTML in posts! Then you can put form with TARGET="malicious site" and fqdn or not fqdn - password will be sent to cracker...
(
Log in to post comments)