Zero-day Vulnerability Database

Change view

Zero-day vulnerabilities discovered: 1

XSS in Mozilla Firefox
CVE-2009-1308

Cross-site scripting

The vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient validation of user-supplied input when processing XBL bindings. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in userтАЩs browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.

Note: the vulnerability was being actively exploited.
i

The vulnerability was exploited against eBay customers in March 2009.

Software: Mozilla Firefox

The vulnerability was exploited against eBay customers in March 2009.