Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
mozilla Firefox 设计缺陷 绕过下载认可限制
Vulnerability Description
Firefox是一款Web浏览器软件。 Firefox 1.0 之前的版本中存在绕过文件下载认可漏洞。 由于不能正确区别用户生成和合成点击事件,这使得远程攻击者可以使用Javascript,在用户使用Alt-click功能时,绕过文件下载的系统提示,在用户不知情的情形下,下载文件。
CVSS Information
N/A
Vulnerability Type
N/A