CVE-2008-2800: XSS
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors involving (1) an event handler attached to an outer window, (2) a SCRIPT element in an unloaded document, or (3) the onreadystatechange handler in conjunction with an XMLHttpRequest.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2800?
CVE-2008-2800 has a moderate severity rating, as it allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting attacks.
How do I fix CVE-2008-2800?
To fix CVE-2008-2800, upgrade Mozilla Firefox to version 2.0.0.15 or later, or SeaMonkey to version 1.1.10 or later.
What versions of Mozilla Firefox are affected by CVE-2008-2800?
Affected versions of Mozilla Firefox include any version prior to 2.0.0.15.
What versions of SeaMonkey are affected by CVE-2008-2800?
Affected versions of SeaMonkey include any version prior to 1.1.10.
What type of attacks can be conducted due to CVE-2008-2800?
CVE-2008-2800 enables remote attackers to perform cross-site scripting (XSS) attacks which can compromise user sessions and sensitive data.