Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The jar: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not follow the Content-Disposition header of the inner URI, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via an uploaded .jar file with a "Content-Disposition: attachment" designation.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox 应用jar:URI 跨站脚本攻击漏洞
Vulnerability Description
Firefox是Mozilla所发布的开源WEB浏览器。 Mozilla Firefox, Thunderbird, SeaMonkey 应用jar:URI 存在跨站脚本攻击漏洞,如果使用jar:主题包装的URI通过Content-disposition: attachment提供内容的话,就会忽略HTTP头解压和显示内容。站点可能依赖于这个HTTP头防范不可信任的内容,因此攻击者可以利用这个漏洞绕过防范机制。
CVSS Information
N/A
Vulnerability Type
N/A