PT-2007-3292 · Mozilla · Firebug
Publicado
2007-04-11
·
Atualizado
2018-10-16
·
CVE-2007-1947
CVSS v2.0
3.5
Baixa
| Vetor | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Firebug extension versions prior to 1.04
Description
A cross-zone scripting issue exists due to the incorrect identification of anonymous JavaScript functions in the DOM templates used by the console.log function. This allows remote attackers to bypass zone restrictions, read arbitrary file:// URIs, or execute arbitrary code in the browser chrome by overwriting the
toString function via a certain function declaration.Recommendations
For Firebug extension versions prior to 1.04, update to version 1.04 or later to resolve the issue. As a temporary workaround, consider disabling the console.log function until a patch is available. Restrict access to the browser chrome to minimize the risk of exploitation. Avoid using the
toString function in sensitive contexts until the issue is resolved.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Firebug