Mozilla Firefox Yoono Extension DOM Event Handler Cross Domain Scripting Vulnerability
BID:37123
Info
Mozilla Firefox Yoono Extension DOM Event Handler Cross Domain Scripting Vulnerability
| Bugtraq ID: | 37123 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 20 2009 12:00AM |
| Updated: | Dec 04 2009 10:54PM |
| Credit: | Roberto Suggi Liverani and Nick Freeman |
| Vulnerable: |
Yoono Yoono Firefox Extension 6.1 |
| Not Vulnerable: |
Yoono Yoono Firefox Extension 6.1.1 |
Discussion
Mozilla Firefox Yoono Extension DOM Event Handler Cross Domain Scripting Vulnerability
The Yoono extension for Mozilla Firefox is prone to a cross-domain scripting vulnerability because it fails to properly sanitize user-supplied input.
Attackers can exploit this issue to run arbitrary code within the 'chrome:' context or run arbitrary commands with the privileges of the user running the affected application. Successful exploits will compromise the affected application and possibly the computer.
Versions prior to Yoono 6.1.1 are vulnerable.
The Yoono extension for Mozilla Firefox is prone to a cross-domain scripting vulnerability because it fails to properly sanitize user-supplied input.
Attackers can exploit this issue to run arbitrary code within the 'chrome:' context or run arbitrary commands with the privileges of the user running the affected application. Successful exploits will compromise the affected application and possibly the computer.
Versions prior to Yoono 6.1.1 are vulnerable.
Exploit / POC
Mozilla Firefox Yoono Extension DOM Event Handler Cross Domain Scripting Vulnerability
An attacker must entice a user to view a malicious webpage with the affected extension.
An attacker must entice a user to view a malicious webpage with the affected extension.
Solution / Fix
Mozilla Firefox Yoono Extension DOM Event Handler Cross Domain Scripting Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Mozilla Firefox Yoono Extension DOM Event Handler Cross Domain Scripting Vulnerability
References:
References:
- Yoono 6.1.1 Release Notes (Yoono)
- Yoono Homepage (Yoono)
- Zero-day vulnerabilities in Firefox extensions discovered (Help Net Security)