Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Gecko-based browsers, including Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8, modify the .href property of stylesheet DOM nodes to the final URI of a 302 redirect, which might allow remote attackers to bypass the Same Origin Policy and read sensitive information from the original URL, such as with Single-Signon systems.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Seamonkey/Firefox 请求重定向 信息泄露漏洞
Vulnerability Description
Mozilla Firefox是美国Mozilla基金会开发的一款开源Web浏览器。 FMozilla Firefox浏览器引擎 2.0.0.12之前版本,SeaMonkey 1.1.8 之前版本,Firefox会对<LINK REL=""stylesheet"" HREF=""..."">请求跟随302重新定向,然后允许通过访问element.sheet.href属性访问目标URL,这可能导致泄露敏感URL参数。
CVSS Information
N/A
Vulnerability Type
N/A