PT-2007-5538 · Mozilla · Firefox
Publicado
2007-08-15
·
Atualizado
2018-10-15
·
CVE-2007-4357
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions 2.0.0.6 and earlier
Description
The issue allows remote attackers to spoof the contents of the status bar via a link to a
data: URI containing an encoded URL. It's worth noting that the severity of this issue has been disputed, as the intended functionality of the status bar allows it to be modified.Recommendations
For Mozilla Firefox versions 2.0.0.6 and earlier, consider disabling the display of the status bar or restricting links to
data: URis as a temporary workaround until a fix is available.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Firefox