Web Hack List

Other nomination

Firefox 2 and WebKit nightly cross-domain image theft

Firefox 2 before 2.0.0.18 and WebKit nightlies could be fooled about an image's origin by loading it via a same-origin URL that 302-redirects to the remote target. The browser treats the result as local, so canvas getImageData reads its pixels and the page steals authenticated images cross-domain. The same trick enumerates installed applications. CVE-2008-5012, MFSA 2008-48.

Record

Researcher
Chris Evans

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Chris Evans, first published at the original source. Preserved copies are kept so the citation survives its host.