V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2008-4068
DEB
HighConfirmedExploit available

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey befor…

CVSS
7.8
High
EPSS
0.00
p49
Published
2008-01-01
Updated
2008-01-01
Description

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML files," and obtain sensitive information and prompt users to write this information into a file, via directory traversal sequences in a resource: URI.

Tags · CWE
CWE-22
CAPEC-64
CAPEC-76
CAPEC-78
CAPEC-79
CAPEC-126
Affected products
DevhelpDevhelpFirefoxFirefoxFirefoxFirefox-3.0IceapeIcedoveIceweaselNssSeamonkeySeamonkeySeamonkeySeamonkeyThunderbirdThunderbirdThunderbirdXulrunnerXulrunnerXulrunner
CVSS vector
AV:N/AC:L/Au:N/C:C/I:N/A:N
Timeline
2008-01-01
Published
2008-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: C
Complete
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.003 · p49
Known exploited (KEV)
No
Known exploits — Сканер-ВС
32466
exploitdb · https://www.exploit-db.com/exploits/32466
Enterprise
9663
exploitdb · https://www.exploit-db.com/exploits/9663
Enterprise
Affected software
ProductVendorStatus
devhelpTracked
devhelpTracked
firefoxTracked
firefoxTracked
firefoxTracked
firefox-3.0Tracked
iceapeTracked
icedoveTracked
iceweaselTracked
nssTracked
seamonkeyTracked
seamonkeyTracked
seamonkeyTracked
seamonkeyTracked
thunderbirdTracked
thunderbirdTracked
thunderbirdTracked
xulrunnerTracked
xulrunnerTracked
xulrunnerTracked