[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248585

 
 

909

 
 

195621

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-2266Date: (C)2005-07-13   (M)2024-03-27


Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
BID-14242
SECUNIA-15549
SECUNIA-15551
SECUNIA-15553
SECUNIA-19823
ADV-2005-1075
DSA-810
FLSA:160202
RHSA-2005:586
RHSA-2005:587
RHSA-2005:601
SUSE-SA:2005:045
SUSE-SA:2006:004
SUSE-SR:2005:018
http://www.mozilla.org/security/announce/mfsa2005-52.html
mozilla-frame-topfocus-xss(21332)
oval:org.mitre.oval:def:100107
oval:org.mitre.oval:def:10712
oval:org.mitre.oval:def:1415
oval:org.mitre.oval:def:773

CPE    38
cpe:/a:mozilla:mozilla:1.4
cpe:/a:mozilla:mozilla:1.3
cpe:/a:mozilla:mozilla:1.6
cpe:/a:mozilla:mozilla:1.5
...
OVAL    1
oval:org.mitre.oval:def:100107

© SecPod Technologies