Lucene search

K
mozillaMozilla FoundationMFSA2006-47
HistoryJul 25, 2006 - 12:00 a.m.

Native DOM methods can be hijacked across domains — Mozilla

2006-07-2500:00:00
Mozilla Foundation
www.mozilla.org
15

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

EPSS

0.138

Percentile

95.7%

A malicious page can hijack native DOM methods on a document object in another domain, which will run the attacker’s script when called by the victim page. This could be used to steal login cookies, password, or other sensitive data on the target page, or to perform actions on behalf of a logged-in user.

Affected configurations

Vulners
Node
mozillafirefoxRange<1.5.0.5
OR
mozillaseamonkeyRange<1.0.3
OR
mozillathunderbirdRange<1.5.0.5
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillaseamonkey*cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
mozillathunderbird*cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

EPSS

0.138

Percentile

95.7%