Уязвимость межсайтового скриптинга (XSS) в Mozilla Firefox, Thunderbird и SeaMonkey из-за некорректного ограничения операций drag-and-drop на javascript: URLs
Описание
в Mozilla Firefox, Thunderbird и SeaMonkey существует уязвимость, связанная с некорректным ограничением операций drag-and-drop на javascript: URLs. Эта уязвимость позволяет злоумышленникам, используя специально сформированную веб-страницу и при содействии пользователя, проводить межсайтовые скриптинговые (XSS) атаки. Проблема связана с так называемым "DragAndDropJacking".
Затронутые версии ПО
- Mozilla Firefox до версии 3.6.28 и 4.x по 10.0
- Firefox ESR 10.x до версии 10.0.3
- Thunderbird до версии 3.1.20 и 5.0 по 10.0
- Thunderbird ESR 10.x до версии 10.0.3
- SeaMonkey до версии 2.8
Тип уязвимости
Межсайтовый скриптинг (XSS)
Ссылки
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Одно из
Одно из
Одно из
Одно из
EPSS
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict drag-and-drop operations on javascript: URLs, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web page, related to a "DragAndDropJacking" issue.
Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict drag-and-drop operations on javascript: URLs, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web page, related to a "DragAndDropJacking" issue.
Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x b ...
Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict drag-and-drop operations on javascript: URLs, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web page, related to a "DragAndDropJacking" issue.
EPSS
4.3 Medium
CVSS2