PT-2007-5246 · Mozilla · Firefox+1

Published

2007-07-27

·

Updated

2018-10-15

·

CVE-2007-4038

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Mozilla Firefox versions prior to 2.0.0.5
Description: The issue allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a mailto URI. This occurs when Mozilla Firefox is running on systems with Thunderbird 1.5 installed and certain URIs are registered. The vulnerability enables the insertion of shell metacharacters into the command line that invokes Thunderbird.exe.
Recommendations: For Mozilla Firefox versions prior to 2.0.0.5, update to version 2.0.0.5 or later to resolve the issue.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-4038
DSA-1338-1

Affected Products

Firefox
Thunderbird