4.3
CVSSv2

CVE-2002-2359

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the FTP view feature in Mozilla 1.0 allows remote malicious users to inject arbitrary web script or HTML via the title tag of an ftp URL.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla mozilla 1.0

mozilla mozilla 1.1

Exploits

source: wwwsecurityfocuscom/bid/5403/info A cross-site scripting vulnerability in Mozilla has been reported When viewing the contents of a FTP site as web content from a ftp:// URL, the directory name is included in the HTML representation It is not adequately sanitized before this occurs An attacker may embed javascript as this value ...