Firefox < 2.0.0.20 Cross Domain Data Theft

This script is Copyright (C) 2008-2017 Tenable Network Security, Inc.


Synopsis :

The remote Windows host contains a web browser that is affected by a
cross domain data theft vulnerability.

Description :

The installed version of Firefox is earlier than 2.0.0.20. Such
versions shipped without a fix for a security issue that was
reportedly fixed in version 2.0.0.19. Specifically :

- A website may be able to access a limited amount of
data from a different domain by loading a same-domain
JavaScript URL which redirects to an off-domain target
resource containing data which is not parsable as
JavaScript. (MFSA 2008-65)

Note that Mozilla is not planning further security / stability
updates for Firefox 2.

See also :

https://www.mozilla.org/en-US/security/advisories/mfsa2008-65/
http://www.nessus.org/u?2f23d29d

Solution :

Upgrade to Firefox 2.0.0.20.

Risk factor :

Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)

Family: Windows

Nessus Plugin ID: 35251 ()

Bugtraq ID:

CVE ID: CVE-2008-5507

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now