First published: Thu Oct 23 2008(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 3.0.1 through 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an ftp:// URL for an HTML document within a (1) JPG, (2) PDF, or (3) TXT file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | =3.0.3 | |
Mozilla Firefox | =3.0.1 | |
Mozilla Firefox | =3.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4723 is considered a moderate severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2008-4723, users should update Mozilla Firefox to version 3.0.4 or later.
CVE-2008-4723 affects HTML documents accessed via ftp:// URLs within JPG, PDF, or TXT files.
Yes, CVE-2008-4723 allows remote attackers to exploit the vulnerability through crafted URLs.
Mozilla Firefox versions 3.0.1, 3.0.2, and 3.0.3 are vulnerable to CVE-2008-4723.