The URL parsing implementation in Mozilla Firefox prior to 42.0 improperly recognizes escaped characters in hostnames within Location headers, which allows remote malicious users to obtain sensitive information via vectors involving a redirect.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
mozilla firefox |