Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox 应用view-source:URI 安全绕过和访问控制漏洞
Vulnerability Description
Firefox是Mozilla所发布的开源WEB浏览器。 Mozilla Firefox, Thunderbird, SeaMonkey 应用view-source:URI 存在安全绕过和访问控制漏洞,在通过view-source:主题加载Adobe Flash主题时,Flash插件错误的将内容来源解释为localhost,这可能导致两个问题: Flash文件可以绕过crossdomain.xml机制限制初始到任意第三方站点的HTTP请求。处理为本地资源的Flash文件可以读写用户机器上的本地共享对象。
CVSS Information
N/A
Vulnerability Type
N/A