Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2008-11-13 03:30
Updated : 2018-11-02 06:50
NVD link : CVE-2008-5024
Mitre link : CVE-2008-5024
JSON object : View
CWE
CWE-91
XML Injection (aka Blind XPath Injection)
Products Affected
mozilla
- thunderbird
- firefox
- seamonkey
canonical
- ubuntu_linux
debian
- debian_linux