Логотип exploitDog
bind:CVE-2006-3352
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2006-3352

Количество 3

Количество 3

nvd логотип

CVE-2006-3352

около 19 лет назад

Cross-domain vulnerability in Mozilla Firefox allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object. NOTE: this description was based on a report that has since been retracted by the original authors. The authors misinterpreted their test results. Other third parties also disputed the original report. Therefore, this is not a vulnerability. It is being assigned a candidate number to provide a clear indication of its status

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2006-3352

около 19 лет назад

Cross-domain vulnerability in Mozilla Firefox allows remote attackers ...

CVSS2: 6.4
EPSS: Низкий
github логотип

GHSA-qcwg-qcmw-7525

больше 3 лет назад

** DISPUTED ** Cross-domain vulnerability in Mozilla Firefox allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object. NOTE: this description was based on a report that has since been retracted by the original authors. The authors misinterpreted their test results. Other third parties also disputed the original report. Therefore, this is not a vulnerability. It is being assigned a candidate number to provide a clear indication of its status.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2006-3352

Cross-domain vulnerability in Mozilla Firefox allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object. NOTE: this description was based on a report that has since been retracted by the original authors. The authors misinterpreted their test results. Other third parties also disputed the original report. Therefore, this is not a vulnerability. It is being assigned a candidate number to provide a clear indication of its status

CVSS2: 6.4
1%
Низкий
около 19 лет назад
debian логотип
CVE-2006-3352

Cross-domain vulnerability in Mozilla Firefox allows remote attackers ...

CVSS2: 6.4
1%
Низкий
около 19 лет назад
github логотип
GHSA-qcwg-qcmw-7525

** DISPUTED ** Cross-domain vulnerability in Mozilla Firefox allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object. NOTE: this description was based on a report that has since been retracted by the original authors. The authors misinterpreted their test results. Other third parties also disputed the original report. Therefore, this is not a vulnerability. It is being assigned a candidate number to provide a clear indication of its status.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу