Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2008-11-13 11:30
Updated : 2018-11-02 13:50
NVD link : CVE-2008-5024
Mitre link : CVE-2008-5024
CVE.ORG link : CVE-2008-5024
JSON object : View
Products Affected
canonical
- ubuntu_linux
mozilla
- firefox
- thunderbird
- seamonkey
debian
- debian_linux
CWE
CWE-91
XML Injection (aka Blind XPath Injection)