Mozilla Firefox "locations.hostname" DOM Property Handling Vulnerability

Discussion started by tlu, Feb 22, 2007.

    Firefox bookmark cross-domain travel vulnerability

    The well-known security expert Michal Zalewski found a new Firefox vulnerability described on

    The problem is already discussed on Bugzilla

    The extension Noscript, which has often been recommended here in the forum, is a good protection against this new vulnerability.
    Ron, you merged my posting into this thread. That's okay - I just want to make sure that this is another vulnerability. It's probably advisable to forbid bookmarklets in Noscript as a countermeasure.
    My error Thomas. It is a separate issue. Post restored.
