CVE-2009-2061
CVE-2009-2061
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
15 Jun 2009Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →