20020806 Mozilla FTP View Cross-Site Scripting Vulnerabilitymailing list
http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0060.html CVE-2002-2359
Mozilla 1.0/1.1 - FTP View Cross-Site Scripting
Record summary
CVE-2002-2359 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting (XSS) vulnerability in the FTP view feature in Mozilla 1.0 allows remote attackers to inject arbitrary web script or HTML via the title tag of an ftp URL.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMozilla 1.0/1.1 - FTP View Cross-Site ScriptingExploitDB exploitby Eiji James YoshidaNot analyzed1 file
References
5bugzilla.mozilla.org
http://bugzilla.mozilla.org/show_bug.cgi?id=154030 multiple-ftp-view-xss(9757)vdb entry
http://www.iss.net/security_center/static/9757.php 5403vdb entry
http://www.securityfocus.com/bid/5403 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-2359