PT-2004-2122 · Netscape · Netscape
Published
2004-12-10
·
Updated
2008-09-05
·
CVE-2004-1160
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Netscape versions 7.x to 7.2
Description:
The issue allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain. This can be demonstrated using a pop-up window on a trusted web site.
Recommendations:
For Netscape versions 7.x to 7.2, consider disabling the ability to inject content from one window into another as a temporary workaround until a patch is available. Restrict access to sensitive web sites to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netscape