Mozilla Firefox是开放源码的WEB浏览器。 Firefox的JavaScript onUnload处理器实现上存在漏洞,恶意网页可能利用此漏洞执行钓鱼攻击。 Firefox没有正确地实现JavaScript onUnload处理器,onUnload事件处理器可以访问所要加载新页面的地址,即使从页面内容以外触发了导航(如通过使用书签、点击返回键、在地址栏中输入地址)。如果书签在URL中包含有敏感信息的话,攻击网页就可以利用这个漏洞;此外攻击者还可以重新定向用户,伪造看起来类似于将要访问站点的页
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2007-1106 | NoMoKeTos PHPBB Module 'includes/functions_nomoketos_rules.php' 远程文件包含漏洞 | |
| CVE-2007-1098 | ScryMUD多个未明漏洞 | |
| CVE-2007-1099 | Dropbear Hostkey dbclient设计错误漏洞 | |
| CVE-2007-1100 | Pickle 'download.php'目录遍历漏洞 | |
| CVE-2007-1101 | PhotoStand 多个跨站脚本攻击漏洞 | |
| CVE-2007-1102 | Photostand敏感信息泄露漏洞 | |
| CVE-2007-1103 | Tor无校验漏洞 | |
| CVE-2007-1104 | PHP Module Implementation 'top.php' PHP远程文件包含漏洞 | |
| CVE-2007-1105 | Extreme PHPBB PHPBB_Root_Path 远程文件包含漏洞 | |
| CVE-2007-1097 | Wiclear onAttachFiles函数文件上传漏洞 | |
| CVE-2007-1107 | Coppermine Photo Gallery 'thumbnails.php' SQL注入漏洞 | |
| CVE-2007-1108 | CS-Gallery 'index.php' 远程文件包含漏洞 | |
| CVE-2007-1109 | PHPWebGallery多个跨站脚本攻击漏洞 | |
| CVE-2007-1110 | Active Calendar 'data/showcode.php'目录遍历漏洞 | |
| CVE-2007-1111 | Active Calendar 多个跨站脚本漏洞 | |
| CVE-2007-1090 | Microsoft Windows资源管理器WMF文件处理拒绝服务漏洞 | |
| CVE-2007-1091 | Microsoft Internet Explorer安全漏洞 | |
| CVE-2007-0776 | Mozilla Firefox/SeaMonkey/Thunderbird多个远程安全漏洞 | |
| CVE-2007-1115 | 多个Web Browser UTF-7 跨域字符设置继承漏洞 | |
| CVE-2007-1116 | Mozilla Firefox CheckLoadURI远程攻击漏洞 |
Showing top 20 of 35 CVEs. View all on vendor page → →
No comments yet