PT-2004-2122 · Netscape · Netscape

Published

2004-12-10

·

Updated

2008-09-05

·

CVE-2004-1160

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Netscape versions 7.x to 7.2
Description: The issue allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain. This can be demonstrated using a pop-up window on a trusted web site.
Recommendations: For Netscape versions 7.x to 7.2, consider disabling the ability to inject content from one window into another as a temporary workaround until a patch is available. Restrict access to sensitive web sites to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1160

Affected Products

Netscape