Mandriva Linux Security Advisory – The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a comment in a title tag, a related issue to CVE-2007-0478. Also affects kdelibs 3.5.6, as per KDE official advisory.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/58491/MDKSA-2007-157.txt
Source: https://packetstormsecurity.com/files/58491/Mandriva-Linux-Security-Advisory-2007.157.html

