Title: Mozilla Browsers onunload SSL Certificate Spoofing
Info
Disclosure
Jul 26, 2004
Discovery
Unknown
Dates
Exploit
Jul 26, 2004
Solution
Unknown
Description
Mozilla and Mozilla Firefox contains a flaw that may allow a malicious user to spoof SSL certification. The issue is triggered when using "onunload" inside a < body> tag and redirection using http-equiv refresh metatag, document.write()
and document.close(), which will spoof a trusted website. By sending a specially crafted webpage, a remote attacker can represent the malicious Web site as that of a trusted site, resulting in a loss of integrity.
Classification
Location:
Remote / Network Access
Impact:
Loss of Integrity
Exploit:
Exploit Public
Disclosure:
OSVDB Verified
Solution
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.