Firefox < Cross Domain Data Theft

This script is Copyright (C) 2008-2017 Tenable Network Security, Inc.

Synopsis :

The remote Windows host contains a web browser that is affected by a
cross domain data theft vulnerability.

Description :

The installed version of Firefox is earlier than Such
versions shipped without a fix for a security issue that was
reportedly fixed in version Specifically :

- A website may be able to access a limited amount of
data from a different domain by loading a same-domain
JavaScript URL which redirects to an off-domain target
resource containing data which is not parsable as
JavaScript. (MFSA 2008-65)

Note that Mozilla is not planning further security / stability
updates for Firefox 2.

See also :

Solution :

Upgrade to Firefox

Risk factor :

Medium / CVSS Base Score : 4.3

Family: Windows

Nessus Plugin ID: 35251 ()

Bugtraq ID:

CVE ID: CVE-2008-5507

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now