Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle injection of an ISINDEX element into an about:blank page, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to redirection to a chrome: URI.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox/SeaMonkey ISINDEX元素设计错误漏洞
Vulnerability Description
Mozilla Firefox/SeaMonkey都是Mozilla发布的开源WEB浏览器。 Mozilla Firefox 3.5.16之前版本,3.6.13之前的3.6.x版本,以及SeaMonkey之前的2.0.11版本没有正确处理ISINDEX元素注入到about:blank页面。远程攻击者可以借助和重定向到chrome: URI有关的向量,利用chrome权限执行任意JavaScript代码。
CVSS Information
N/A
Vulnerability Type
N/A