4.3
CVSSv2

CVE-2008-4723

Published: 23/10/2008 Updated: 24/10/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 3.0.1 up to and including 3.0.3 allow remote malicious users to inject arbitrary web script or HTML via an ftp:// URL for an HTML document within a (1) JPG, (2) PDF, or (3) TXT file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 3.0.3

mozilla firefox 3.0.2

mozilla firefox 3.0.1

Vendor Advisories

Debian Bug report logs - #520052 webkit: CVE-2008-4723 cross-site scripting vulnerability Package: webkit; Maintainer for webkit is (unknown); Reported by: Michael Gilbert <michaelsgilbert@gmailcom> Date: Tue, 17 Mar 2009 02:30:01 UTC Severity: grave Tags: security Found in version webkit/101-4 Fixed in version webk ...

Exploits

source: wwwsecurityfocuscom/bid/31855/info Mozilla Firefox 3 is prone to a cross-site scripting weakness that arises because the software fails to handle specially crafted files served using the FTP protocol Successfully exploiting this issue may allow an attacker to execute arbitrary script code in the browser of an unsuspecting user i ...