You are here: Known Vulnerabilities in Mozilla Products (Firefox 18.104.22.168) > MFSA 2008-10
Mozilla Foundation Security Advisory 2008-10
Title: URL token stealing via stylesheet redirect
Announced: February 7, 2008
Reporter: Martin Straka
Products: Firefox, SeaMonkey
Fixed in: Firefox 22.214.171.124
Security researcher Martin Straka reported
that Gecko-based browsers update the
.href property of stylesheet
DOM nodes to reflect the final URI of the stylesheet after following
any 302 redirects (much as the document.location property is updated).
This differs from other browsers and could potentially reveal sensitive
URL parameters, such as those used by Single-signon sytems, to scripts
on the page.