|
[Japanese]
|
JVNDB-2007-000779
|
MouseoverDictionary vulnerable to arbitrary script execution
|
MouseoverDictionary, an add-on for Mozilla Firefox, contains a vulnerability that allows an attacker to execute an arbitrary script.
MouseoverDictionary, an add-on mouseover English-Japanese dictionary for Mozilla Firefox, contains a vulnerability that allows an attacker to execute an arbitrary script on the user's web browser as it does not handle the sidebar HTML page properly.
|
Base Metrics:
5.8 (Medium)
[IPA Score]
- Access Vector: Network
- Access Complexity: Medium
- Authentication: None
- Confidentiality Impact: Partial
- Integrity Impact: Partial
- Availability Impact: None
|
|
|
Ichiro Maruta
- MouseoverDictionary Version 0.6.1 and earlier
|
|
An attacker could execute an arbitrary script in Mozilla Firefox when the user uses MouseoverDictionary. Depending on the script, the attacker may be able to view arbitrary files on the client PC.
|
[Update the Software]
Apply the latest updates provided by the developer.
|
Ichiro Maruta
- Mouseover Dictionary : News
|
- Cross-site Scripting(CWE-79) [NVD Evaluation]
|
- CVE-2007-5459
|
- JVN : JVN#63304072
- National Vulnerability Database (NVD) : CVE-2007-5459
- Secunia Advisory : SA27195
- SecurityFocus : 26053
- ISS X-Force Database : 37184
|
[2008/05/21]
Web page published
|