Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Mozilla Firefox before 22.0 does not properly implement certain DocShell inheritance behavior for the sandbox attribute of an IFRAME element, which allows remote attackers to bypass intended access restrictions via a FRAME element within an IFRAME element.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox 权限许可和访问控制漏洞
Vulnerability Description
Mozilla Firefox是美国Mozilla基金会开发的一款开源Web浏览器。 Mozilla Firefox 21.0及之前的版本中存在漏洞,该漏洞源于程序对IFRAME元素的沙箱属性没有正确实现特定的DocShell继承行为。远程攻击者可通过IFRAME元素中的FRAME元素利用该漏洞绕过既定的访问限制。
CVSS Information
N/A
Vulnerability Type
N/A