CVE-2017-7783
HIGHFirefox < 55.0 - Denial of Service via Long Username in URL Authentication Prompt
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-7783. PoCs published by Amit Sangra.
AI-analyzed exploit summary This exploit leverages a denial of service vulnerability in Mozilla Firefox < 55 by crafting a URL with an excessively long username, causing the browser to hang or crash. The PoC forces the victim to view attacker-supplied content before triggering the DoS.
Description
If a long user name is used in a username/password combination in a site URL (such as " http://UserName:[email protected]"), the resulting modal prompt will hang in a non-responsive state or crash, causing a denial of service. This vulnerability affects Firefox < 55.
Exploits (1)
This exploit leverages a denial of service vulnerability in Mozilla Firefox < 55 by crafting a URL with an excessively long username, causing the browser to hang or crash. The PoC forces the victim to view attacker-supplied content before triggering the DoS.
References (5)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H