The child frames in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 inherit the default charset from the parent window, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T12:43:21.663Z
Reserved: 2007-02-16T00:00:00
Link: CVE-2007-0996

No data.

Status : Modified
Published: 2007-02-27T02:28:00.000
Modified: 2024-11-21T00:27:14.893
Link: CVE-2007-0996
