Lunascape Support Forum

Find the answers you need and discuss anything about Lunascape.
It is currently Mon May 21, 2012 6:32 am

All times are UTC - 8 hours [ DST ]




Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 1 post ] 
Author Message
 Post subject: IE Related Security Hole
PostPosted: Tue Sep 22, 2009 7:44 pm 
Site Admin

Joined: Tue Mar 10, 2009 4:35 am
Posts: 43
We have investigated the following security holes and found that it is a problem rooted in IE6,7 and 8. This affects Trident engine, but not Gecko or Webkit. We'd ask Trident users to be cautious. Please apply Windows Update once Microsoft issues its patch for this problem.

"Lunascape 5.1.3 and 5.1.4 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page. NOTE: a related attack was reported in which an arbitrary file: URL is shown."
http://web.nvd.nist.gov/view/vuln/detai ... -2009-3005


Top
 Profile  
 
Display posts from previous:  Sort by  
Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 1 post ] 

All times are UTC - 8 hours [ DST ]


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
SubIPB3.0 Designed by Lee Gao - http://6.dot.ch/.
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
Copyright Lunascape Co., Ltd. All rights reserved.