Mozilla is said to be working on a fix for
a flaw called
Reverse Cross-Site Request that, when exploited, can expose saved passwords
to attackers. RCSR attacks are also actively targeting Microsoft Internet
Explorer, however a flaw in Firefox makes the attack much more likely to
succeed. The Password Manager component of FireFox can be exploited to send a
username and password combination to an attacker's computer without the user's
knowledge. The vulnerability is caused due to the Password Manager not properly
checking the URL before automatically filling in saved user credentials into
forms. This may be exploited to steal user credentials via malicious forms in
the same domain. The vulnerability is confirmed in version 2.0.0. Other versions
may also be affected.
Solution: Disable the "Remember passwords for sites" option in the preferences.