Email us! Subscribe to Liquidmatrix!

Mozilla Firefox Firebug Extension XSS

If you are a user of the Firefox Firebug add-on please read this and upgrade.

From Secunia:

Description:
pdp has reported a vulnerability in the Firebug extension for Mozilla Firefox, which can be exploited by malicious people to compromise a vulnerable system.

Firebug does not properly sanitise input passed to the “console.log()” function. This can be exploited to e.g. execute arbitrary script code within the “chrome:” context by tricking a user into visiting a malicious website.

The vulnerability is reported in versions prior to 1.02.

Solution:
Update to version 1.02.

Article Link

Firebug Addon Link

Tags: , , ,

Tag It:
  • Digg
  • del.icio.us
  • Slashdot
  • Technorati
  • SphereIt
  • StumbleUpon
  • Fark
  • YahooMyWeb
  • Furl
  • Spurl
  • Ma.gnolia
  • NewsVine
Related Articles:

  • Security Patches For Mozilla Firefox, Thunderbird and Seamonkey
  • Mozilla Readies Firefox Security Patch
  • Firefox 3 Release Candidate 1 Now Available
  • Firefox and Thunderbird Updates!
  • Mozilla to End Support for Older (1.0.x) Firefox Versions
  • Leave a Comment