V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2008-4066
DEB
MediumConfirmedExploit available

Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mecha…

CVSS
4.3
Medium
EPSS
0.01
p78
Published
2008-01-01
Updated
2008-01-01
Description

Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are ignored by the HTML parser, as demonstrated by a "jav&#56325ascript" sequence, aka "HTML escaped low surrogates bug."

Tags · CWE
XSS
CWE-79
CAPEC-63
CAPEC-85
CAPEC-209
CAPEC-588
CAPEC-591
CAPEC-592
Affected products
Firefox
CVSS vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Timeline
2008-01-01
Published
2008-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: P
Partial
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.012 · p78
Known exploited (KEV)
No
Known exploits — Сканер-ВС
32466
exploitdb · https://www.exploit-db.com/exploits/32466
Enterprise
9663
exploitdb · https://www.exploit-db.com/exploits/9663
Enterprise
Affected software
ProductVendorStatus
devhelpTracked
firefoxTracked
firefox-3.0Tracked
iceapeTracked
iceapeTracked
icedoveTracked
iceweaselTracked
seamonkeyTracked
seamonkeyTracked
seamonkeyTracked
seamonkeyTracked
thunderbirdTracked
thunderbirdTracked
thunderbirdTracked
xulrunnerTracked
xulrunnerTracked
xulrunner-1.9Tracked
firefox*Tracked