vendor:
FirePHP Firefox plugin
by:
Wireghoul
9,3
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: FirePHP Firefox plugin
Affected Version From: All versions up to and including 0.7.1
Affected Version To: All versions up to and including 0.7.1
Patch Exists: YES
Related CWE: N/A
CPE: firefox_plugin:firephp
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2013
Firephp firefox plugin RCE
FirePHP Firefox plugin is vulnerable to Remote Code Execution. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious XUL code to launch calc.exe. This vulnerability affects all versions up to and including 0.7.1.
Mitigation:
Upgrade to the latest version of FirePHP Firefox plugin.