Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-4039

Опубликовано: 27 июл. 2007
Источник: nvd
CVSS3: 9.8
CVSS2: 4.3
EPSS Низкий

Описание

Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mozilla:mozilla:*:*:*:*:*:*:*:*

EPSS

Процентиль: 79%
0.02014
Низкий

9.8 Critical

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 19 лет назад

Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670.

CVSS3: 9.8
debian
около 19 лет назад

Argument injection vulnerability involving Mozilla, when certain URIs ...

CVSS3: 9.8
github
больше 4 лет назад

Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670.

EPSS

Процентиль: 79%
0.02014
Низкий

9.8 Critical

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79
CWE-79