| Definition Id: oval:org.mitre.oval:def:100053 |
Date: 2007-04-23 |
| Title: |
Mozilla Inactive Tab Form Data Theft Vulnerability |
| Description: |
Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported using form fields, which allows remote attackers to steal sensitive data that is intended for other sites, which could facilitate phishing attacks. |
| Version: |
5 |
Class: |
vulnerability |
| Status: |
ACCEPTED |
Reference(s): |
CVE-2004-1381
|
| Family: |
windows |
| Platform(s): |
Microsoft Windows NT Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 |
Product(s): |
mozilla Firefox |
| Definition Synopsis: |
- Mozilla Firefox version 0.9 or earlier is installed
- OR Mozilla Suite version 1.7.4 or earlier is installed
|