Lucene search

K
cvelistMitreCVELIST:CVE-2010-1197
HistoryJun 23, 2010 - 6:00 p.m.

CVE-2010-1197

2010-06-2318:00:00
mitre
www.cve.org
4

AI Score

8.6

Confidence

High

EPSS

0.004

Percentile

73.4%

Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, does not properly handle situations in which both “Content-Disposition: attachment” and “Content-Type: multipart” are present in HTTP headers, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an uploaded HTML document.

References