|
|||
Rule General Information |
---|
Release Date: | 2013-05-02 | |
Rule Name: | WEB-CLIENT Mozilla Firefox Character Processing Cross Site Scripting (CVE-2008-4066) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are ignored by the HTML parser. | |
Impact: | Remote code execution | |
Affected OS: | Windows, Solaris, Other Unix, FreeBSD, Linux | |
Reference: | CVE-2008-4066 |
|
Solutions |
---|
Update vendor's patch. |