vendor:
Firefox
by:
milw0rm.com
5.5
CVSS
MEDIUM
Arbitrary File Write
73
CWE
Product Name: Firefox
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:mozilla:firefox
Platforms Tested: Windows
2005
Firefox Profile Directory Arbitrary File Write
This exploit allows anonymous users to gain administrator rights by placing the exe file in the Firefox profile directory and browsing a site with phpbb. It replaces a specific string in the cookies.txt file to modify user privileges. If something goes wrong, clearing cookies is recommended.
Mitigation:
Regularly update Firefox to the latest version, avoid visiting untrusted websites, and clear cookies if any suspicious behavior is observed.