V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2008-5024
DEB
HighConfirmedExploit available

Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not prop…

CVSS
7.5
High
EPSS
0.07
p91
Published
2008-01-01
Updated
2008-01-01
Description

Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.

Tags · CWE
CWE-91
CAPEC-83
CAPEC-250
Affected products
DevhelpFirefoxFirefoxFirefoxFirefox-3.0IceapeIcedoveIceweaselNssNssSeamonkeySeamonkeySeamonkeySeamonkeyThunderbirdThunderbirdThunderbirdXulrunnerXulrunnerXulrunner
CVSS vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Timeline
2008-01-01
Published
2008-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.072 · p91
Known exploited (KEV)
No
Known exploits — Сканер-ВС
32466
exploitdb · https://www.exploit-db.com/exploits/32466
Enterprise
9663
exploitdb · https://www.exploit-db.com/exploits/9663
Enterprise
Affected software
ProductVendorStatus
devhelpTracked
firefoxTracked
firefoxTracked
firefoxTracked
firefox-3.0Tracked
iceapeTracked
icedoveTracked
iceweaselTracked
nssTracked
nssTracked
seamonkeyTracked
seamonkeyTracked
seamonkeyTracked
seamonkeyTracked
thunderbirdTracked
thunderbirdTracked
thunderbirdTracked
xulrunnerTracked
xulrunnerTracked
xulrunnerTracked