Lucene search

K
mozillaMozilla FoundationMFSA2005-34
HistoryApr 15, 2005 - 12:00 a.m.

PLUGINSPAGE privileged javascript execution — Mozilla

2005-04-1500:00:00
Mozilla Foundation
www.mozilla.org
22

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.627

Percentile

97.8%

When a webpage requires a plugin that is not installed the user can click to launch the Plugin Finder Service (PFS) to find an appropriate plugin. If the service does not have an appropriate plugin the EMBED tag is checked for a PLUGINSPAGE attribute, and if one is found the PFS dialog will contain a “manual install” button that will load the PLUGINSPAGE url.

Affected configurations

Vulners
Node
mozillafirefoxRange<1.0.3

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.627

Percentile

97.8%