Window Injection Spoofing
- February 24, 2005
- Firefox, Mozilla Suite
- Fixed in
- Firefox 1.0.1
- Mozilla Suite 1.7.6
A website can inject content into a popup opened by another site if the target name of the popup window is known. An attacker who knows you are going to visit that other site could spoof the contents of the popup.
Open windows can now be targeted by name only by the site whose content is in the window and the site which opened the window if different. Other sites attempting to target the same named window will instead get a new unnamed window.
Do not browse trusted sites after browsing untrusted sites