PT-2007-4918 · Microsoft+3 · Internet Explorer+3

Jesper Johansson

·

Published

2007-07-10

·

Updated

2024-12-12

·

CVE-2007-3670

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer (affected versions not specified)
Description The issue allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a FirefoxURL or FirefoxHTML URI. This occurs when Internet Explorer invokes firefox.exe and fails to properly delimit the URL argument, potentially affecting other protocol handlers in Internet Explorer as well.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-3670
HPSBUX02153
OPENSUSE-SU-2014_1100-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:10601-1
OPENSUSE-SU-2024:14572-1
ROSA-SA-2024-2370

Affected Products

Firefox
Hp-Ux
Internet Explorer
Suse