Thread-topic: [SA18703] Mozilla Suite XML Injection and Code Execution Vulnerabilities
>
>
> TITLE:
> Mozilla Suite XML Injection and Code Execution Vulnerabilities
>
> SECUNIA ADVISORY ID:
> SA18703
>
> VERIFY ADVISORY:
>
>
> CRITICAL:
> Highly critical
>
> IMPACT:
> Cross Site Scripting, System access
>
> WHERE:
> From remote
>
> SOFTWARE:
> Mozilla 1.7.x
>
> Mozilla 1.6
>
> Mozilla 1.5
>
> Mozilla 1.4
>
> Mozilla 1.3
>
> Mozilla 1.2
>
> Mozilla 1.1
>
> Mozilla 1.0
>
> Mozilla 0.x
>
>
> DESCRIPTION:
> Two vulnerabilities have been reported in Mozilla Suite, which can be
> exploited by malicious people to conduct cross-site scripting attacks
> and potentially compromise a user's system.
>
> For more information, see #1 and #4 in:
> SA18700
>
> SOLUTION:
> Disable JavaScript, except for trusted web sites.
>
> OTHER REFERENCES:
> SA18700:
>
>