Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3799-mwjc-pmj8

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows remote attackers to bypass the same-domain policy by tricking a user into saving a bookmarklet with a data: scheme, which is executed in the context of the last visited web page.

Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows remote attackers to bypass the same-domain policy by tricking a user into saving a bookmarklet with a data: scheme, which is executed in the context of the last visited web page.

EPSS

Процентиль: 77%
0.01048
Низкий

Связанные уязвимости

ubuntu
больше 18 лет назад

Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows remote attackers to bypass the same-domain policy by tricking a user into saving a bookmarklet with a data: scheme, which is executed in the context of the last visited web page.

nvd
больше 18 лет назад

Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows remote attackers to bypass the same-domain policy by tricking a user into saving a bookmarklet with a data: scheme, which is executed in the context of the last visited web page.

debian
больше 18 лет назад

Mozilla Firefox 2.0.0.1 and earlier does not prompt users before savin ...

EPSS

Процентиль: 77%
0.01048
Низкий