vendor:
Firebug
by:
Thor Larholm
7.5
CVSS
HIGH
Script Code Injection
Unknown
CWE
Product Name: Firebug
Affected Version From: Versions prior to 1.04
Affected Version To: Unknown
Patch Exists: YES
Related CWE: Unknown
CPE: a:firebug:firebug
Platforms Tested:
Unknown
Firebug script-code-injection vulnerability
Firebug is prone to a script-code-injection vulnerability because it fails to adequately escape user-supplied data. An attacker can exploit this issue to execute arbitrary script code in the context of the application.
Mitigation:
Upgrade to Firebug v1.0.4 or greater