Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla多个产品E4X文档 XML注入攻击漏洞
Vulnerability Description
Mozilla多个产品的E4X文档存在XML注入攻击漏洞。Mozilla Firefox、Thunderbird以及SeaMonkey没有正确的逸出用于XML处理的引号字符,这使得远程攻击者可以借助一个E4X文档中默认的命名空间,来执行XML注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A