CVE-2005-1476
Firefox 1.0.3 - XSS
Title source: llmDescription
Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Edward Gagnon · htmlremotewindows
https://www.exploit-db.com/exploits/986
References (19)
Scores
EPSS
0.4976
EPSS Percentile
97.8%
Classification
Status
draft
Affected Products (1)
mozilla/firefox
< 1.0.3
Timeline
Published
May 09, 2005
Tracked Since
Feb 18, 2026