First published: Wed Jul 13 2005(Updated: )
Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | =0.8 | |
Firefox | =0.9 | |
Firefox | =0.9-rc | |
Firefox | =0.9.1 | |
Firefox | =0.9.2 | |
Firefox | =0.9.3 | |
Firefox | =0.10 | |
Firefox | =0.10.1 | |
Firefox | =1.0 | |
Firefox | =1.0.1 | |
Firefox | =1.0.2 | |
Firefox | =1.0.3 | |
Firefox | =1.0.4 | |
Mozilla Firefox | =1.3 | |
Mozilla Firefox | =1.4 | |
Mozilla Firefox | =1.4-alpha | |
Mozilla Firefox | =1.4.1 | |
Mozilla Firefox | =1.5 | |
Mozilla Firefox | =1.5-alpha | |
Mozilla Firefox | =1.5-rc1 | |
Mozilla Firefox | =1.5-rc2 | |
Mozilla Firefox | =1.5.1 | |
Mozilla Firefox | =1.6 | |
Mozilla Firefox | =1.6-alpha | |
Mozilla Firefox | =1.6-beta | |
Mozilla Firefox | =1.7 | |
Mozilla Firefox | =1.7-alpha | |
Mozilla Firefox | =1.7-beta | |
Mozilla Firefox | =1.7-rc1 | |
Mozilla Firefox | =1.7-rc2 | |
Mozilla Firefox | =1.7-rc3 | |
Mozilla Firefox | =1.7.1 | |
Mozilla Firefox | =1.7.2 | |
Mozilla Firefox | =1.7.3 | |
Mozilla Firefox | =1.7.5 | |
Mozilla Firefox | =1.7.6 | |
Mozilla Firefox | =1.7.7 | |
Mozilla Firefox | =1.7.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2266 is classified as a medium-severity vulnerability due to its potential for information disclosure.
To fix CVE-2005-2266, upgrade to Mozilla Firefox version 1.0.5 or later and Mozilla version 1.7.9 or later.
CVE-2005-2266 exploits a flaw in the same origin policy, allowing a child frame to access elements in a parent frame from a different domain.
CVE-2005-2266 can allow remote attackers to steal sensitive information such as cookies and passwords.
CVE-2005-2266 affects various versions of Mozilla Firefox prior to 1.0.5 and various versions of Mozilla prior to 1.7.9.