Synopsis
The remote host may give an attacker information useful for future attacks.
Description
The remote host is running a version of the Mozilla browser that is prone to a path-disclosure issue. Javascript may be used to communicate with the plugin. It is possible to access the filename of the plugin using JavaScript, and on some systems this also will expose the full path to the plugin. If the plugin is located in the home directory of the user, this also has the potential to disclose their username.
Solution
Upgrade to the latest version of Mozilla or Netscape
Plugin Details
Risk Information
Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Temporal Vector: CVSS:3.0/E:U/RL:U/RC:C
Reference Information
BID: 5741