Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka "Firesearching 2."
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:56
Type | Values Removed | Values Added |
---|---|---|
References | () ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt - | |
References | () http://secunia.com/advisories/14938 - Patch, Vendor Advisory | |
References | () http://secunia.com/advisories/14992 - Patch, Vendor Advisory | |
References | () http://secunia.com/advisories/14996 - Patch, Vendor Advisory | |
References | () http://www.mikx.de/firesearching/ - Exploit | |
References | () http://www.mozilla.org/security/announce/mfsa2005-38.html - Vendor Advisory | |
References | () http://www.redhat.com/support/errata/RHSA-2005-383.html - Patch, Vendor Advisory | |
References | () http://www.redhat.com/support/errata/RHSA-2005-384.html - | |
References | () http://www.redhat.com/support/errata/RHSA-2005-386.html - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/13211 - Exploit, Patch | |
References | () http://www.securityfocus.com/bid/15495 - | |
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=290037 - Patch | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/20125 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9961 - |
Information
Published : 2005-05-02 04:00
Updated : 2024-11-20 23:56
NVD link : CVE-2005-1157
Mitre link : CVE-2005-1157
CVE.ORG link : CVE-2005-1157
JSON object : View
Products Affected
mozilla
- firefox
- mozilla
netscape
- navigator
CWE