PT-2008-4615 · Mozilla+1 · Firefox+1
Ben Turner
+2
·
Publicado
2008-07-16
·
Atualizado
2017-08-08
·
CVE-2008-3198
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Mozilla Firefox versions 3.x before 3.0.1
Description:
The issue allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors. This can be demonstrated by injection into a XUL error page, which can potentially be leveraged to execute arbitrary code.
Recommendations:
For Mozilla Firefox versions 3.x before 3.0.1, update to version 3.0.1 or later to resolve the issue.
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Firefox
Red Hat