CVE-2009-1839
Mozilla Firefox < 3.0.11 - File URL Principal Bypass via Location Bar
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1839. PoCs published by Jordi Chancel.
AI-analyzed exploit summary This exploit demonstrates a location bar spoofing vulnerability in Mozilla Firefox by injecting content into a blank page while displaying a misleading URL. It leverages JavaScript to manipulate the location bar and stop page loading, creating a spoofing attack.
Description
Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document, aka a "file-URL-to-file-URL scripting" attack.
Exploits (1)
This exploit demonstrates a location bar spoofing vulnerability in Mozilla Firefox by injecting content into a blank page while displaying a misleading URL. It leverages JavaScript to manipulate the location bar and stop page loading, creating a spoofing attack.