PT-2008-4615 · Mozilla+1 · Firefox+1

Ben Turner

+2

·

Publicado

2008-07-16

·

Atualizado

2017-08-08

·

CVE-2008-3198

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Mozilla Firefox versions 3.x before 3.0.1
Description: The issue allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors. This can be demonstrated by injection into a XUL error page, which can potentially be leveraged to execute arbitrary code.
Recommendations: For Mozilla Firefox versions 3.x before 3.0.1, update to version 3.0.1 or later to resolve the issue.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-3198
DSA-1614-1
RHSA-2008:0597
RHSA-2008_0597

Produtos afetados

Firefox
Red Hat