The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows remote user-assisted attackers to execute privileged code by tricking a user into installing missing plugins and selecting the "Manual Install" button, then using nested javascript: URLs. NOTE: the manual install button is used for downloading software from a remote web site, so this issue would not cross privilege boundaries if the user progresses to the point of installing malicious software from the attacker-controlled site.
CVSS Details
- CVSS 3.1 Base Score: 5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/mozilla-firefox. | Oct 30, 2017 | Jun 2, 2006 |
| Mfsa2006 36 | — | Upgrade to Mozilla Firefox version 1.5.0.4 | Jun 14, 2012 | Jun 2, 2006 |
| Ubuntu | — | Upgrade mozilla-browserUpgrade firefoxUpgrade mozilla-mailnewsUpgrade mozilla-psmUpgrade mozilla-thunderbirdUpgrade mozilla-firefox | Nov 8, 2024 | Jun 2, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub