Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2005-07-13T04:00:00
Updated: 2024-08-07T22:22:47.768Z
Reserved: 2005-07-13T00:00:00
Link: CVE-2005-2269
Vulnrichment
No data.
NVD
Status : Modified
Published: 2005-07-13T04:00:00.000
Modified: 2024-11-20T23:59:10.620
Link: CVE-2005-2269
Redhat