URL token stealing via stylesheet redirect
- February 7, 2008
- Martin Straka
- Firefox, SeaMonkey
- Fixed in
- Firefox 220.127.116.11
- SeaMonkey 1.1.8
Security researcher Martin Straka reported
that Gecko-based browsers update the
.href property of stylesheet
DOM nodes to reflect the final URI of the stylesheet after following
any 302 redirects (much as the document.location property is updated).
This differs from other browsers and could potentially reveal sensitive
URL parameters, such as those used by Single-signon sytems, to scripts
on the page.