CVE-2010-1197

CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 0.39 % (74th)
0.39% Progress
Affected Products 2
Advisories 9

Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, does not properly handle situations in which both "Content-Disposition: attachment" and "Content-Type: multipart" are present in HTTP headers, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an uploaded HTML document.

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2010-06-24 12:30:01
(14 years ago)
Updated Date
2017-09-19 01:30:35
(7 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 3.5 cpe:2.3:a:mozilla:firefox:3.5
  Mozilla Firefox 3.5.1 cpe:2.3:a:mozilla:firefox:3.5.1
  Mozilla Firefox 3.5.2 cpe:2.3:a:mozilla:firefox:3.5.2
  Mozilla Firefox 3.5.3 cpe:2.3:a:mozilla:firefox:3.5.3
  Mozilla Firefox 3.5.4 cpe:2.3:a:mozilla:firefox:3.5.4
  Mozilla Firefox 3.5.5 cpe:2.3:a:mozilla:firefox:3.5.5
  Mozilla Firefox 3.5.6 cpe:2.3:a:mozilla:firefox:3.5.6
  Mozilla Firefox 3.5.7 cpe:2.3:a:mozilla:firefox:3.5.7
  Mozilla Firefox 3.5.9 cpe:2.3:a:mozilla:firefox:3.5.9

Configuration #2

    CPE23 From Up To
  Mozilla Seamonkey 2.0.4 and prior versions cpe:2.3:a:mozilla:seamonkey <= 2.0.4
  Mozilla Seamonkey 1.0 cpe:2.3:a:mozilla:seamonkey:1.0
  Mozilla Seamonkey 1.0 Alpha cpe:2.3:a:mozilla:seamonkey:1.0:alpha
  Mozilla Seamonkey 1.0 Beta cpe:2.3:a:mozilla:seamonkey:1.0:beta
  Mozilla Seamonkey 1.0.1 cpe:2.3:a:mozilla:seamonkey:1.0.1
  Mozilla Seamonkey 1.0.2 cpe:2.3:a:mozilla:seamonkey:1.0.2
  Mozilla Seamonkey 1.0.3 cpe:2.3:a:mozilla:seamonkey:1.0.3
  Mozilla Seamonkey 1.0.4 cpe:2.3:a:mozilla:seamonkey:1.0.4
  Mozilla Seamonkey 1.0.5 cpe:2.3:a:mozilla:seamonkey:1.0.5
  Mozilla Seamonkey 1.0.6 cpe:2.3:a:mozilla:seamonkey:1.0.6
  Mozilla Seamonkey 1.0.7 cpe:2.3:a:mozilla:seamonkey:1.0.7
  Mozilla Seamonkey 1.0.8 cpe:2.3:a:mozilla:seamonkey:1.0.8
  Mozilla Seamonkey 1.0.9 cpe:2.3:a:mozilla:seamonkey:1.0.9
  Mozilla Seamonkey 1.1 cpe:2.3:a:mozilla:seamonkey:1.1
  Mozilla Seamonkey 1.1 Alpha cpe:2.3:a:mozilla:seamonkey:1.1:alpha
  Mozilla Seamonkey 1.1 Beta cpe:2.3:a:mozilla:seamonkey:1.1:beta
  Mozilla Seamonkey 1.1.1 cpe:2.3:a:mozilla:seamonkey:1.1.1
  Mozilla Seamonkey 1.1.2 cpe:2.3:a:mozilla:seamonkey:1.1.2
  Mozilla Seamonkey 1.1.3 cpe:2.3:a:mozilla:seamonkey:1.1.3
  Mozilla Seamonkey 1.1.4 cpe:2.3:a:mozilla:seamonkey:1.1.4
  Mozilla Seamonkey 1.1.5 cpe:2.3:a:mozilla:seamonkey:1.1.5
  Mozilla Seamonkey 1.1.6 cpe:2.3:a:mozilla:seamonkey:1.1.6
  Mozilla Seamonkey 1.1.7 cpe:2.3:a:mozilla:seamonkey:1.1.7
  Mozilla Seamonkey 1.1.8 cpe:2.3:a:mozilla:seamonkey:1.1.8
  Mozilla Seamonkey 1.1.9 cpe:2.3:a:mozilla:seamonkey:1.1.9
  Mozilla Seamonkey 1.1.10 cpe:2.3:a:mozilla:seamonkey:1.1.10
  Mozilla Seamonkey 1.1.11 cpe:2.3:a:mozilla:seamonkey:1.1.11
  Mozilla Seamonkey 1.1.12 cpe:2.3:a:mozilla:seamonkey:1.1.12
  Mozilla Seamonkey 1.1.13 cpe:2.3:a:mozilla:seamonkey:1.1.13
  Mozilla Seamonkey 1.1.14 cpe:2.3:a:mozilla:seamonkey:1.1.14
  Mozilla Seamonkey 1.1.15 cpe:2.3:a:mozilla:seamonkey:1.1.15
  Mozilla Seamonkey 1.1.16 cpe:2.3:a:mozilla:seamonkey:1.1.16
  Mozilla Seamonkey 1.1.17 cpe:2.3:a:mozilla:seamonkey:1.1.17
  Mozilla Seamonkey 1.1.18 cpe:2.3:a:mozilla:seamonkey:1.1.18
  Mozilla Seamonkey 1.1.19 cpe:2.3:a:mozilla:seamonkey:1.1.19
  Mozilla Seamonkey 2.0 cpe:2.3:a:mozilla:seamonkey:2.0
  Mozilla Seamonkey 2.0 Alpha 1 cpe:2.3:a:mozilla:seamonkey:2.0:alpha_1
  Mozilla Seamonkey 2.0 Alpha 2 cpe:2.3:a:mozilla:seamonkey:2.0:alpha_2
  Mozilla Seamonkey 2.0 Alpha 3 cpe:2.3:a:mozilla:seamonkey:2.0:alpha_3
  Mozilla Seamonkey 2.0 Beta 1 cpe:2.3:a:mozilla:seamonkey:2.0:beta_1
  Mozilla Seamonkey 2.0 Beta 2 cpe:2.3:a:mozilla:seamonkey:2.0:beta_2
  Mozilla Seamonkey 2.0 Rc1 cpe:2.3:a:mozilla:seamonkey:2.0:rc1
  Mozilla Seamonkey 2.0 Rc2 cpe:2.3:a:mozilla:seamonkey:2.0:rc2
  Mozilla Seamonkey 2.0.1 cpe:2.3:a:mozilla:seamonkey:2.0.1
  Mozilla Seamonkey 2.0.2 cpe:2.3:a:mozilla:seamonkey:2.0.2
  Mozilla Seamonkey 2.0.3 cpe:2.3:a:mozilla:seamonkey:2.0.3

Configuration #3

    CPE23 From Up To
  Mozilla Firefox 3.6 cpe:2.3:a:mozilla:firefox:3.6
  Mozilla Firefox 3.6.2 cpe:2.3:a:mozilla:firefox:3.6.2
  Mozilla Firefox 3.6.3 cpe:2.3:a:mozilla:firefox:3.6.3
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...