First published: Mon Feb 26 2007(Updated: )
Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 ignores trailing invalid HTML characters in attribute names, which allows remote attackers to bypass content filters that use regular expressions.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla SeaMonkey | <=1.0.7 | |
Mozilla Firefox | =1.5.0.10 | |
Mozilla Firefox | =2.0 | |
Mozilla Firefox | =2.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.