Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-1878

Опубликовано: 06 апр. 2007
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug extension before 1.03 for Mozilla Firefox allows remote attackers to bypass zone restrictions, read arbitrary file:// URIs, or execute arbitrary code in the browser chrome, as demonstrated via the runFile function, related to lack of HTML escaping in the property name.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:parakey_inc.:firebug:1.01:*:*:*:*:*:*:*
cpe:2.3:a:parakey_inc.:firebug:1.02:*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.01821
Низкий

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug extension before 1.03 for Mozilla Firefox allows remote attackers to bypass zone restrictions, read arbitrary file:// URIs, or execute arbitrary code in the browser chrome, as demonstrated via the runFile function, related to lack of HTML escaping in the property name.

EPSS

Процентиль: 83%
0.01821
Низкий

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other