PT-2005-3364 · None · Greasemonkey
Mark Pilgrim
·
Publicado
2005-08-04
·
Atualizado
2017-07-11
·
CVE-2005-2455
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Greasemonkey versions prior to 0.3.5
Description
The issue allows remote web servers to read arbitrary files via a GET request to a file:// URL in the
GM xmlhttpRequest API function. It also enables listing installed scripts using GM scripts, and obtaining sensitive information via GM setValue and GM getValue functions.Recommendations
For versions prior to 0.3.5, update to version 0.3.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
GM xmlhttpRequest function and limiting access to GM scripts, GM setValue, and GM getValue functions until the update is applied.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Greasemonkey