Oval Definition:oval:org.mitre.oval:def:1855
Revision Date:2007-05-09Version:3
Title:Mozilla Cross-site JavaScript Injection Using Event Handlers
Description:Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) using window.__proto__ to extend eval, aka "cross-site JavaScript injection".
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2006-1741
Platform(s):Microsoft Windows 2000
Microsoft Windows Server 2003
Microsoft Windows XP
Product(s):mozilla
Definition Synopsis
  • Mozilla Firefox version 1.0.7 or earlier is installed
  • Mozilla Firefox version 1.0.7 or earlier is installed
  • AND Firefox version 1.0.7 or earlier is installed
  • OR Mozilla Thunderbird version 1.0.7 or earlier is installed
  • Mozilla Thunderbird version 1.0.7 or earlier is installed
  • AND Mozilla Thunderbird version 1.0.7 or earlier is installed
  • OR Mozilla Suite version 1.7.12 or earlier is installed
  • Mozilla Suite version 1.7.12 or earlier is installed
  • AND Mozilla Suite version 1.7.12 or earlier is installed
  • OR A pre-release of SeaMonkey 1.0 is installed
  • A pre-release of SeaMonkey 1.0 is installed
  • AND A pre-release of SeaMonkey 1.0 is installed
  • BACK