vendor:
Mozilla Firefox
by:
Unknown
9
CVSS
CRITICAL
Remote Code Execution
CWE
Product Name: Mozilla Firefox
Affected Version From: Firefox 3.6.3
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2010-1199
CPE: a:mozilla:firefox:3.6.3
Metasploit:
https://www.rapid7.com/db/vulnerabilities/mozilla-thunderbird-cve-2010-1199/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0499/, https://www.rapid7.com/db/vulnerabilities/mfsa2010-30-cve-2010-1199/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2010-1199/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2010-1199/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2010-1199/, https://www.rapid7.com/db/vulnerabilities/mozilla-seamonkey-cve-2010-1199/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0544/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0545/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0500/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0501/
Platforms Tested:
2010
Mozilla Firefox XSLT Sort Remote Code Execution Vulnerability
This exploit targets a vulnerability in Mozilla Firefox version 3.6.3. It allows an attacker to execute arbitrary code remotely.
Mitigation:
Upgrade to a newer version of Mozilla Firefox.