Mozilla FTP View Cross-Site Scripting Vulnerability
10 Aug. 2002
Summary
Mozilla allows running of malicious scripts due to a bug in 'FTP view' feature. The vulnerability occurs whenever you click on a malicious link while viewing a file in the 'FTP view'. In the case where the FTP server and the HTTP server are on the same address, the issue is even more dangerous, this is because the cookie may be modified by the attacker.
Workaround:
Use the latest version of Mozilla 1.1 Beta or disable JavaScript.
Vendor status:
The Mozilla security bug group was notified on 22 June 2002.
They have fixed the problem, and the fix will be included in Mozilla 1.0.1. (The fix has already been included in the latest version of Mozilla 1.1 Beta.)