firefox-firebug
Page content
- Author: voroskoi
- Vulnerable: 1.01-1
- Unaffected: 1.05-1terminus1
Two vulnerabilities have been reported in the Firebug extension for Mozilla Firefox, which can be exploited by malicious people to compromise a vulnerable system.
- Input passed to the “console.log()” function is not properly sanitised and can be exploited to e.g. execute arbitrary script code within the “chrome:” context by tricking a user into visiting a malicious website.
- Results of the “toString” method when processing function objects are not properly sanitised before being used. This can be exploited to e.g. execute arbitrary script code within the “chrome:” context by overriding the “toString” method with a specially crafted function.
- Bug Tracker URL: http://bugs.frugalware.org/task/1917