Mozilla has made its bug code named #360493 public. The bug is present in the Password Manager Feature of Firefox 2.0.

The flaw supplies your passwords stored on one page of your domain to another page on the domain.

Netcraft discovered the flaw on October 27. Security firm Stopgap Solutions have recommended the users to avoid using the Password Manager and the Master Password Timeout features of Firefox 2.0.

Mozilla has confirmed this as bug number 360493, and said they are already working on a fix for version 2.0.0.1 or 2.0.0.2.

Click Here to see a description of this new type of attack.

Via: slashdot