5
CVSSv2

CVE-2004-1381

Published: 20/10/2004 Updated: 11/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Firefox prior to 1.0 and Mozilla prior to 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported using form fields, which allows remote malicious users to steal sensitive data that is intended for other sites, which could facilitate phishing attacks.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 0.10.1

mozilla firefox 0.8

mozilla mozilla 1.3

mozilla mozilla 1.4

mozilla mozilla 1.6

mozilla mozilla 1.7

mozilla firefox 0.9.2

mozilla firefox 0.9.3

mozilla mozilla 1.5.1

mozilla mozilla 1.5

mozilla mozilla 1.7.1

mozilla mozilla 1.7.2

mozilla firefox 0.9

mozilla firefox 0.9.1

mozilla mozilla 1.4.1

mozilla firefox 0.10

mozilla mozilla

mozilla mozilla 1.7.3

Vendor Advisories

USN-149-1 fixed some vulnerabilities in the Ubuntu 504 (Hoary Hedgehog) version of Firefox The version shipped with Ubuntu 410 (Warty Warthog) is also vulnerable to these flaws, so it needs to be upgraded as well Please see ...

Exploits

<b>Test Your Browser</b><br> <br> Open the link below in a new tab, then try to type data into form fields on the CitiBank website<br> <br> <a href="wwwcitibankcom/" onMouseOver="setInterval('documentmyformuserinputfocus();', 10);">Open this Link in New Tab</a> ...