Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2007-1878

Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug extension before 1.03 for Mozilla Firefox allows remote attackers to bypass zone restrictions, read arbitrary file:// URIs, or execute arbitrary code in the browser chrome, as demonstrated via the runFile function, related to lack of HTML escaping in the property name.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.018
EPSS Ranking 81.7%
CVSS Severity
CVSS v2 Score 6.8
References
Products affected by CVE-2007-1878


Contact Us

Shodan ® - All rights reserved