[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-3089Date: (C)2007-06-06   (M)2023-12-22


Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECTRACK-1018412
SUNALERT-103177
http://www.securityfocus.com/archive/1/470446/100/0/threaded
20070701-01-P
http://www.securityfocus.com/archive/1/474226/100/0/threaded
http://www.securityfocus.com/archive/1/474542/100/0/threaded
SUNALERT-201516
BID-24286
SECUNIA-25589
SECUNIA-26072
SECUNIA-26095
SECUNIA-26103
SECUNIA-26106
SECUNIA-26107
SECUNIA-26149
SECUNIA-26151
SECUNIA-26159
SECUNIA-26179
SECUNIA-26204
SECUNIA-26205
SECUNIA-26211
SECUNIA-26216
SECUNIA-26258
SECUNIA-26271
SECUNIA-26460
SREASON-2781
SECUNIA-28135
OSVDB-38024
ADV-2007-2564
ADV-2007-4256
DSA-1337
DSA-1338
DSA-1339
GLSA-200708-09
HPSBUX02153
MDKSA-2007:152
RHSA-2007:0722
RHSA-2007:0723
RHSA-2007:0724
SUSE-SA:2007:049
TA07-199A
USN-490-1
VU#143297
firefox-iframe-security-bypass(34701)
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txt
http://lcamtuf.coredump.cx/ifsnatch/
http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html
http://www.mozilla.org/security/announce/2007/mfsa2007-20.html
https://bugzilla.mozilla.org/show_bug.cgi?id=381300
https://bugzilla.mozilla.org/show_bug.cgi?id=382686
oval:org.mitre.oval:def:11122

CPE    41
cpe:/a:mozilla:firefox:1.5.0.10
cpe:/a:mozilla:firefox:1.5.0.11
cpe:/a:mozilla:firefox:1.5.0.4
cpe:/a:mozilla:firefox:1.5.0.3
...

© SecPod Technologies