Secunia Logo
 
CVE Reference: CVE-2005-1531
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-1531

Description:
Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."

CVE Status:
Candidate

References:

ST
  1013962
  1013963

SCO

REDHAT
  http://www.redhat.com/support/errata/RHSA-2005-435.html
  http://www.redhat.com/support/errata/RHSA-2005-434.html

OVAL
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100015

CONFIRM
  http://www.mozilla.org/security/announce/mfsa2005-43.html

BID
  13641
  15495


Return to the previous page.