Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2008-4066

Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are ignored by the HTML parser, as demonstrated by a "jav&#56325ascript" sequence, aka "HTML escaped low surrogates bug."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 78.6%
CVSS Severity
CVSS v2 Score 4.3
References
Products affected by CVE-2008-4066
  • Mozilla » Firefox » Version: 2.0.0.14
    cpe:2.3:a:mozilla:firefox:2.0.0.14
  • Mozilla » Firefox » Version: 2.0.0.15
    cpe:2.3:a:mozilla:firefox:2.0.0.15
  • Mozilla » Firefox » Version: 2.0.0.16
    cpe:2.3:a:mozilla:firefox:2.0.0.16


Contact Us

Shodan ® - All rights reserved