[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-1157Date: (C)2005-05-02   (M)2023-12-22


Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka "Firesearching 2."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
BID-13211
SECUNIA-14938
SECUNIA-14992
SECUNIA-14996
BID-15495
RHSA-2005:383
RHSA-2005:384
RHSA-2005:386
SCOSA-2005.49
http://www.mikx.de/firesearching/
http://www.mozilla.org/security/announce/mfsa2005-38.html
https://bugzilla.mozilla.org/show_bug.cgi?id=290037
mozilla-plugin-xss(20125)
oval:org.mitre.oval:def:9961

CPE    35
cpe:/a:mozilla:mozilla:1.4
cpe:/a:mozilla:mozilla:1.3
cpe:/a:mozilla:mozilla:1.6
cpe:/a:mozilla:mozilla:1.5
...

© SecPod Technologies