Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-4039

Опубликовано: 27 июл. 2007
Источник: nvd
CVSS3: 9.8
CVSS2: 4.3
EPSS Низкий

Описание

Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mozilla:mozilla:*:*:*:*:*:*:*:*

EPSS

Процентиль: 64%
0.00479
Низкий

9.8 Critical

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 18 лет назад

Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670.

CVSS3: 9.8
debian
больше 18 лет назад

Argument injection vulnerability involving Mozilla, when certain URIs ...

CVSS3: 9.8
github
больше 3 лет назад

Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670.

EPSS

Процентиль: 64%
0.00479
Низкий

9.8 Critical

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79
CWE-79