55163vdb entry
http://osvdb.org/55163 CVE-2009-1839
Mozilla Firefox - Location Bar Spoofing
Record summary
CVE-2009-1839 has a selected CVSS score of 5.4; EIP currently links 1 catalogued exploit.
Description
Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document, aka a "file-URL-to-file-URL scripting" attack.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMozilla Firefox - Location Bar SpoofingExploitDB exploitby Jordi ChancelNot analyzed1 file
References
Showing 12 of 1935331Third-party advisory
http://secunia.com/advisories/35331 35415Third-party advisory
http://secunia.com/advisories/35415 35431Third-party advisory
http://secunia.com/advisories/35431 35468Third-party advisory
http://secunia.com/advisories/35468 SSA:2009-167-01Vendor advisory
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468 264308Vendor advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1 DSA-1820Vendor advisory
http://www.debian.org/security/2009/dsa-1820 mozilla.orgConfirmation
http://www.mozilla.org/security/announce/2009/mfsa2009-30.html 35326vdb entry
http://www.securityfocus.com/bid/35326 35386vdb entry
http://www.securityfocus.com/bid/35386 ADV-2009-1572vdb entry
http://www.vupen.com/english/advisories/2009/1572