PT-2007-3224 · Mozilla · Firebug
Published
2007-04-06
·
Updated
2018-10-16
·
CVE-2007-1878
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Firebug extension versions prior to 1.03
Description:
A cross-zone scripting issue exists in the DOM templates used by the console.log function, allowing remote attackers to bypass zone restrictions. This can lead to reading arbitrary file:// URIs or executing arbitrary code in the browser chrome. The issue is related to a lack of HTML escaping in the property name, as demonstrated via the
runFile function.Recommendations:
For Firebug extension versions prior to 1.03, update to version 1.03 or later to resolve the issue. As a temporary workaround, consider disabling the use of the console.log function with DOM templates until a patch is available. Restrict access to sensitive files and directories to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Firebug