Netscape/Mozilla Navigator Plugin Path Disclosure (deprecated)

low Nessus Network Monitor Plugin ID 1313

Synopsis

The remote host may give an attacker information useful for future attacks.

Description

The remote host is running a version of the Mozilla browser that is prone to a path-disclosure issue. Javascript may be used to communicate with the plugin. It is possible to access the filename of the plugin using JavaScript, and on some systems this also will expose the full path to the plugin. If the plugin is located in the home directory of the user, this also has the potential to disclose their username.

Solution

Upgrade to the latest version of Mozilla or Netscape

Plugin Details

Severity: Low

ID: 1313

Family: SMTP Clients

Published: 8/20/2004

Updated: 3/6/2019

Reference Information

BID: 5741