Common Vulnerabilities and Exposures assigned an identifier CVE-2010-1126 to the following vulnerability: Name: CVE-2010-1126 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1126 Assigned: 20100326 Reference: BUGTRAQ:20100313 ...because you can't get enough of clickjacking Reference: URL: http://www.securityfocus.com/archive/1/archive/1/510070/100/0/threaded The JavaScript implementation in WebKit allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended form field in a visible frame, via certain calls to the focus method.
Direct link to Michal Zalewski's demo: http://lcamtuf.coredump.cx/focus-webkit/ Closing this notabug, as the issue can't be reproduced with current webkitgtk / qtwebkit browsers in RHEL / Fedora.