Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in the MozSearch plugin implementation in Mozilla Firefox before 3.0.9 allows user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SearchForm element.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox 插件"MozSearch" 跨站脚本攻击漏洞
Vulnerability Description
Firefox是Mozilla所发布的开源WEB浏览器。 Mozilla Firefox插件"MozSearch" 存在跨站脚本攻击漏洞,可以使用SearchForm值中的javascript: URI创建恶意的MozSearch插件,在执行空搜索时将这个URI用作默认的登录页面。如果攻击者能给诱骗用户安装这个恶意插件并执行空搜索,就会在当前打开的页面执行SearchForm javascript: URI。
CVSS Information
N/A
Vulnerability Type
N/A