16043Third-party advisory
http://secunia.com/advisories/16043 CVE-2005-2262
Mozilla Firefox 1.0.4 - 'Set As Wallpaper' Code Execution
Record summary
CVE-2005-2262 has a selected CVSS score of 5.1; EIP currently links 1 catalogued exploit.
Description
Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper" (in Firefox) or "Set as Background" (in Netscape) context menu on an image URL that is really a javascript: URL with an eval statement, aka "Firewalling."
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMozilla Firefox 1.0.4 - 'Set As Wallpaper' Code ExecutionExploitDB exploitby Michael KraxNot analyzed1 file
References
Showing 12 of 1516044Third-party advisory
http://secunia.com/advisories/16044 P-252Third-party advisoryGovernment resource
http://www.ciac.org/ciac/bulletins/p-252.shtml mikx.de
http://www.mikx.de/firewalling mozilla.orgConfirmation
http://www.mozilla.org/security/announce/mfsa2005-47.html networksecurity.fi
http://www.networksecurity.fi/advisories/netscape-multiple-issues.html SUSE-SR:2005:018Vendor advisory
http://www.novell.com/linux/security/advisories/2005_18_sr.html SUSE-SA:2005:045Vendor advisory
http://www.novell.com/linux/security/advisories/2005_45_mozilla.html RHSA-2005:586Vendor advisory
http://www.redhat.com/support/errata/RHSA-2005-586.html securiteam.com
http://www.securiteam.com/securitynews/5ZP0E0UGAK.html 14242vdb entry
http://www.securityfocus.com/bid/14242 ADV-2005-1075vdb entry
http://www.vupen.com/english/advisories/2005/1075