Vulnerabilities > CVE-2004-2225 - Unspecified vulnerability in Mozilla Firefox
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN mozilla
nessus
Summary
Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitrary files in the download directory via a crafted data: URI that is not properly handled when the user clicks the Save button.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 8 |
Nessus
NASL family | Windows |
NASL id | MOZILLA_FIREFOX_FILES_RM.NASL |
description | The installed version of Firefox is earlier than 0.10.1. Such versions contain a weakness that could allow a remote attacker to delete arbitrary files in the user download directory. To exploit this, an attacker would need to trick a user into viewing a malicious web page. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15408 |
published | 2004-10-02 |
reporter | This script is Copyright (C) 2004-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/15408 |
title | Firefox < 0.10.1 Download Directory Arbitrary File Deletion |
code |
|
References
- http://secunia.com/advisories/12708
- http://secunia.com/advisories/12708
- http://securitytracker.com/id?1011501
- http://securitytracker.com/id?1011501
- http://www.mozilla.org/projects/security/older-vulnerabilities.html#firefox0.10.1
- http://www.mozilla.org/projects/security/older-vulnerabilities.html#firefox0.10.1
- http://www.osvdb.org/10478
- http://www.osvdb.org/10478
- http://www.securityfocus.com/bid/11311
- http://www.securityfocus.com/bid/11311
- https://bugzilla.mozilla.org/show_bug.cgi?id=259708
- https://bugzilla.mozilla.org/show_bug.cgi?id=259708