Saturday, June 25, 2005

malicious web sites to spoof dialog boxes

Secunia Research has discovered a vulnerability in various browsers, which can be exploited by malicious web sites to spoof dialog boxes.

The problem is that JavaScript dialog boxes do not display or include their origin, which allows a new window to open e.g. a prompt dialog box, which appears to be from a trusted site.



The vulnerability has been confirmed in Mozilla 1.7.8, FireFox 1.04, and Camino 0.8.4. Prior versions may also be affected.

Solution:
Do not browse untrusted web sites while browsing trusted sites.