PT-2007-5246 · Mozilla · Firefox+1

Publicado

2007-07-27

·

Atualizado

2018-10-15

·

CVE-2007-4038

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Mozilla Firefox versions prior to 2.0.0.5
Description: The issue allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a mailto URI. This occurs when Mozilla Firefox is running on systems with Thunderbird 1.5 installed and certain URIs are registered. The vulnerability enables the insertion of shell metacharacters into the command line that invokes Thunderbird.exe.
Recommendations: For Mozilla Firefox versions prior to 2.0.0.5, update to version 2.0.0.5 or later to resolve the issue.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-4038
DSA-1338-1

Produtos afetados

Firefox
Thunderbird