Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Netscape/Mozilla Navigator Plugin Path Disclosure (deprecated)

Medium

Synopsis

The remote host may give an attacker information useful for future attacks.

Description

The remote host is running a version of the Mozilla browser that is prone to a path-disclosure issue. Javascript may be used to communicate with the plugin. It is possible to access the filename of the plugin using JavaScript, and on some systems this also will expose the full path to the plugin. If the plugin is located in the home directory of the user, this also has the potential to disclose their username.

Solution

Upgrade to the latest version of Mozilla or Netscape