CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
Percentile
95.9%
Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving
bookmarklets, which allows remote attackers to bypass the same-domain
policy by tricking a user into saving a bookmarklet with a data: scheme,
which is executed in the context of the last visited web page.
Author | Note |
---|---|
jdstrand | 1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1 lists: New security/stability upstream release (v2.0.0.6) - 1.8.0.13 prepatches and mentions many CVEs, but not this one. still not fixed per asac (on any release) |