Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2010-2751

EPSS 0.36% · P58
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2010-2751

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The nsDocShell::OnRedirectStateChange function in docshell/base/nsDocShell.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to spoof the SSL security status of a document via vectors involving multiple requests, a redirect, and the history.back and history.forward JavaScript functions.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Mozilla Firefox history.back()和history.forward()方式地址栏欺骗漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mozilla Firefox是美国Mozilla基金会开发的一款开源Web浏览器。 Firefox在访问安全网页时显示位置栏的方式存在漏洞。恶意服务器可以利用这个漏洞以看起来来自安全服务器的方式呈现数据,即使数据非来自安全的服务器。 如果要利用这个漏洞,服务器首先要将对明文资源的请求重新定向到有效SSL/TLS证书后的其他资源,之后对原始明文资源的第二次请求所回复的响应就不是重新定向,而是包含history.back()和history.forward()的JavaScript,导致显示明文资源时地址栏
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2010-2751

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-2751

登录查看更多情报信息。

Same Patch Batch · n/a · 2010-07-30 · 40 CVEs total

CVE-2010-2917AJ Square AJ Article 'index.php'多个跨站脚本攻击漏洞
CVE-2010-1791Apple Safari WebKit整数符号错误漏洞
CVE-2010-1792Apple Safari WebKit正则表达式缓冲区溢出漏洞
CVE-2010-1793Apple Safari WebKit多个释放后使用漏洞
CVE-2010-1796Apple Safari个人地址簿自动填充功能信息泄露漏洞
CVE-2010-2752Mozilla Firefox/Thunderbird/SeaMonkey nsCSSValue::Array索引整数溢出漏洞
CVE-2010-2753Mozilla Firefox/Thunderbird/SeaMonkey TreeSelection悬停指针远程代码执行漏洞
CVE-2010-2914Nessus Nessus Web Server插件'nessusd_www_server.nbin'跨站脚本攻击漏洞
CVE-2010-2915AJ Square AJ HYIP PRIME 'welcome.php'SQL注入漏洞
CVE-2010-2916AJ Square AJ HYIP MERIDIAN 'news.php'SQL注入漏洞
CVE-2010-1790Apple Safari WebKit HTML文档拒绝服务漏洞
CVE-2010-2918Visocrea Visites组件SQL注入漏洞
CVE-2010-2919Joomlaxt StaticXT SQL注入漏洞
CVE-2010-2920Foobla Suggestions组件路径遍历漏洞
CVE-2010-2921Photoindochina Golf Course Guide组件SQL注入漏洞
CVE-2010-2922AKY Blog 'default.asp'SQL注入漏洞
CVE-2010-2923Prasanna YouTube组件SQL注入漏洞
CVE-2010-2924Silvercover myLinksDump插件 'myLDlinker.php'SQL注入漏洞
CVE-2010-2925Open Freeway 'index.php' ecPath SQL注入漏洞
CVE-2010-2926Solucija sNews 'index.php'SQL注入漏洞

Showing top 20 of 40 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2010-2751

No comments yet


Leave a comment