First published: Mon Jun 13 2005(Updated: )
A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | =1.0.3 | |
Mozilla Firefox | =1.7.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1937 is classified as a moderate severity vulnerability due to the potential for cross-site scripting attacks.
To mitigate CVE-2005-1937, users should upgrade to a patched version of Firefox or Mozilla that addresses this vulnerability.
CVE-2005-1937 affects Firefox version 1.0.3 and Mozilla version 1.7.7.
CVE-2005-1937 allows attackers to inject arbitrary JavaScript from one page into the frameset of another, enabling possible spoofing attacks.
No, CVE-2005-1937 is a regression of a previously identified vulnerability addressed in CVE-2004-XXXXX.