CVE-2005-1476

Firefox 1.0.3 - XSS

Title source: llm

Description

Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Edward Gagnon · htmlremotewindows
https://www.exploit-db.com/exploits/986

Scores

EPSS 0.4976
EPSS Percentile 97.8%

Classification

Status draft

Affected Products (1)

mozilla/firefox < 1.0.3

Timeline

Published May 09, 2005
Tracked Since Feb 18, 2026