Retired: Mozilla Firefox OuterHTML Redirection Handling Information Disclosure Vulnerability
BID:18734
CVE-2006-3352 |Info
Retired: Mozilla Firefox OuterHTML Redirection Handling Information Disclosure Vulnerability
| Bugtraq ID: | 18734 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2006 12:00AM |
| Updated: | Jun 30 2006 08:49PM |
| Credit: | Plebo Aesdi Nael <[email protected]> discovered this issue. |
| Vulnerable: |
Mozilla Firefox 1.5 beta 2 Mozilla Firefox 1.5 beta 1 Mozilla Firefox 1.5 Mozilla Firefox 1.0.8 Mozilla Firefox 1.0.7 Mozilla Firefox 1.0.6 Mozilla Firefox 1.0.5 Mozilla Firefox 1.0.5 Mozilla Firefox 1.0.4 Mozilla Firefox 1.0.3 Mozilla Firefox 1.0.2 Mozilla Firefox 1.0.1 Mozilla Firefox 1.0 Mozilla Firefox 0.10.1 Mozilla Firefox 0.10 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 rc Mozilla Firefox 0.9 Mozilla Firefox 0.8 Mozilla Firefox Preview Release Mozilla Firefox 1.5.0.4 Mozilla Firefox 1.5.0.3 Mozilla Firefox 1.5.0.2 Mozilla Firefox 1.5.0.2 Mozilla Firefox 1.5.0.1 |
| Not Vulnerable: | |
Discussion
Retired: Mozilla Firefox OuterHTML Redirection Handling Information Disclosure Vulnerability
Mozilla Firefox is prone to an information-disclosure vulnerability because it fails to properly enforce cross-domain policies.
This issue may allow attackers to access arbitrary websites in the context of a targeted user's browser session. This may allow attackers to perform actions in web applications with the privileges of exploited users or to gain access to potentially sensitive information. This may aid attackers in further attacks.
Further reports indicate that this issue does not affect Firefox as reported. Therefore this BID is being retired.
Mozilla Firefox is prone to an information-disclosure vulnerability because it fails to properly enforce cross-domain policies.
This issue may allow attackers to access arbitrary websites in the context of a targeted user's browser session. This may allow attackers to perform actions in web applications with the privileges of exploited users or to gain access to potentially sensitive information. This may aid attackers in further attacks.
Further reports indicate that this issue does not affect Firefox as reported. Therefore this BID is being retired.
Exploit / POC
Retired: Mozilla Firefox OuterHTML Redirection Handling Information Disclosure Vulnerability
Attackers use standard utilities and webserver applications to exploit this issue.
Attackers use standard utilities and webserver applications to exploit this issue.
Solution / Fix
Retired: Mozilla Firefox OuterHTML Redirection Handling Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Further reports indicate that this issue does not affect Firefox as reported. Therefore this BID is being retired.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Further reports indicate that this issue does not affect Firefox as reported. Therefore this BID is being retired.
References
Retired: Mozilla Firefox OuterHTML Redirection Handling Information Disclosure Vulnerability
References:
References:
- Bojan Zdrnja (Bojan Zdrnja)
- IE_ONE_MINOR_ONE_MAJOR (Plebo Aesdi Nael
) - Mozilla Firefox Home Page (Mozilla)