cve/2008/CVE-2008-4060.md
2024-08-08 18:49:29 +00:00

852 B

CVE-2008-4060

Description

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome privileges, via vectors related to (1) the document.loadBindingDocument function and (2) XSLT.

POC

Reference

Github

No PoCs found on GitHub currently.