>> Mozilla Firefox JAR Protocol Client-Side Cross Site Scripting Vulnerability
Title : Mozilla Firefox JAR Protocol Client-Side Cross Site Scripting Vulnerability VUPEN ID : VUPEN/ADV-2007-3818 CVE ID : CVE-2007-5947
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-11-09
Technical Description
A vulnerability has been identified in Mozilla Firefox, which could be exploited to conduct cross site scripting attacks and gain knowledge of sensitive information. This issue is caused by an input and origin validation error in the implementation of the "jar" protocol, which could be exploited by attackers to cause malicious scripting code to be executed by a user's browser in the security context of an arbitrary Web site by tricking the user into following a specially crafted link.