Lucene search

K
ubuntucveUbuntu.comUB:CVE-2005-1157
HistoryMay 02, 2005 - 12:00 a.m.

CVE-2005-1157

2005-05-0200:00:00
ubuntu.com
ubuntu.com
12

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.019

Percentile

88.5%

Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows
remote attackers to replace existing search plugins with malicious ones
using sidebar.addSearchEngine and the same filename as the target engine,
which may not be displayed in the GUI, which could then be used to execute
malicious script, aka “Firesearching 2.”

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.019

Percentile

88.5%