Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 3.0.1 through 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an ftp:// URL for an HTML document within a (1) JPG, (2) PDF, or (3) TXT file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | 3.0.3 | 3.0.3.x |
| mozilla / firefox | 3.0.1 | 3.0.1.x |
| mozilla / firefox | 3.0.2 | 3.0.2.x |