Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."
References
Configurations
History
No history.
Information
Published : 2005-02-07 05:00
Updated : 2025-04-03 01:03
NVD link : CVE-2005-0231
Mitre link : CVE-2005-0231
CVE.ORG link : CVE-2005-0231
JSON object : View
Products Affected
mozilla
- firefox
CWE