Back

MEDIUM

firefox: remote arbitrary web script or HTML injection via an ftp:// URL

Published Oct 23, 2008

Description

Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 3.0.1 through 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an ftp:// URL for an HTML document within a (1) JPG, (2) PDF, or (3) TXT file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Affected products

Remediation

Red Hat statement

Red Hat does not consider this to be a security flaw. Firefox is handling the ftp:// URL as expected.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 23, 2008
Updated Sep 16, 2024
Reserved Oct 23, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Oct 21, 2008