Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2009-1839Mozilla Firefox vulnerability

CWE-2647 documents6 sources
Severity
5.4MEDIUMNVD
EPSS
15.2%
top 5.39%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJun 12
Latest updateMay 2

Description

Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document, aka a "file-URL-to-file-URL scripting" attack.

CVSS vector

AV:N/AC:H/C:C/I:N/A:NExploitability: 4.9 | Impact: 6.9

Affected Packages1 packages

NVDmozilla/firefox3.0.10+12

Patches

🔴Vulnerability Details

1
GHSA
GHSA-mx4x-6484-3f7v: Mozilla Firefox 3 before 32022-05-02

💥Exploits & PoCs

2
Exploit-DB
Mozilla Firefox - Location Bar Spoofing2009-12-18
Exploit-DB
WordPress MU < 2.7 - 'HOST' HTTP Header Cross-Site Scripting2009-03-10

📋Vendor Advisories

2
Ubuntu
Firefox and Xulrunner vulnerabilities2009-06-12
Red Hat
Firefox information disclosure flaw2009-06-11

💬Community

1
Bugzilla
CVE-2009-1839 Firefox information disclosure flaw2009-06-01