First published: Fri Jul 23 2004(Updated: )
The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FirebirdSQL | =0.7 | |
Mozilla Mozilla | =1.6 | |
Netscape Navigator | =7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0718 is considered a medium severity vulnerability due to its impact on web security.
To fix CVE-2004-0718, users should update to the latest version of the affected browsers or switch to a more secure browser.
CVE-2004-0718 affects Mozilla 1.6, Firebird 0.7, Firefox 0.8, and Netscape Navigator 7.1.
CVE-2004-0718 can facilitate web site spoofing attacks and other content injection vulnerabilities.
CVE-2004-0718 is a frame injection vulnerability that allows cross-domain content injection.