vendor:
Navigator
by:
Florian Wesch
7,5
CVSS
HIGH
Cross-site Scripting (XSS)
79
CWE
Product Name: Navigator
Affected Version From: Netscape 4.76
Affected Version To: Netscape 4.76
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Netscape 4.76 gif comment flaw
Due to a flaw in Navigator's security code, all URLs in the about: protocol are considered to be part of the same domain. If arbitrary Javascript code is placed in a GIF's comment field, it is treated like a normal HTML page. The Javascript code will run from the image information page in the internal about: 'domain'. This issue has also been reported in commented JPEG files.
Mitigation:
Ensure that all URLs in the about: protocol are not considered to be part of the same domain.