vendor:
Firefox
by:
MrDoug
3.3
CVSS
MEDIUM
Clickjacking
N/A
CWE
Product Name: Firefox
Affected Version From: 3.0.5
Affected Version To: 3.0.5
Patch Exists: NO
Related CWE: N/A
CPE: a:mozilla:firefox:3.0.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Firefox 3.0.5 Status Bar Obfuscation / Clickjacking
This exploit uses the Firefox 3.0.5 Status Bar Obfuscation technique to redirect users to milw0rm.com when they click on a link to google.com. The exploit uses a div element with a mouseover event to redirect the user to milw0rm.com. The div element is positioned at the exact coordinates of the mouse pointer when the user clicks on the link.
Mitigation:
Users should be aware of the potential for clickjacking attacks and should be cautious when clicking on links. Additionally, web developers should use the X-Frame-Options header to prevent clickjacking attacks.