First published: Mon Feb 07 2005(Updated: )
Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0231 is considered a moderate severity vulnerability due to the potential to bypass browser security mechanisms.
To fix CVE-2005-0231, users should upgrade to a later version of Firefox that addresses this vulnerability.
CVE-2005-0231 allows attackers to bypass the JavaScript security model when manipulating URLs, potentially leading to malicious activity.
No, CVE-2005-0231 affects only Firefox version 1.0, and later versions have patched this vulnerability.
CVE-2005-0231 impacts user security by enabling potential exploitation through unauthorized JavaScript execution in tabs.