Lucene search

K
freebsdFreeBSD2E28CEFB-2AEE-11DA-A263-0001020EED82
HistorySep 06, 2005 - 12:00 a.m.

firefox & mozilla -- command line URL shell command injection

2005-09-0600:00:00
vuxml.freebsd.org
15

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.962

Percentile

99.5%

A Secunia Advisory reports:

Peter Zelezny has discovered a vulnerability in Firefox,
which can be exploited by malicious people to compromise a
user’s system.
The vulnerability is caused due to the shell script used
to launch Firefox parsing shell commands that are enclosed
within backticks in the URL provided via the command
line. This can e.g. be exploited to execute arbitrary
shell commands by tricking a user into following a
malicious link in an external application which uses
Firefox as the default browser.

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.962

Percentile

99.5%