CVE-2017-5420

A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an attacker to spoof an existing page without the malicious page's address being displayed correctly. This vulnerability affects Firefox < 52.
References
Link Resource
https://www.mozilla.org/security/advisories/mfsa2017-05/ Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1284395 Exploit Issue Tracking Patch Vendor Advisory
http://www.securitytracker.com/id/1037966 Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/96692 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

Information

Published : 2018-06-11 14:29

Updated : 2018-08-07 10:51


NVD link : CVE-2017-5420

Mitre link : CVE-2017-5420


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

mozilla

  • firefox