PT-2007-5246 · Mozilla · Firefox+1
Published
2007-07-27
·
Updated
2018-10-15
·
CVE-2007-4038
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Mozilla Firefox versions prior to 2.0.0.5
Description:
The issue allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a
mailto URI. This occurs when Mozilla Firefox is running on systems with Thunderbird 1.5 installed and certain URIs are registered. The vulnerability enables the insertion of shell metacharacters into the command line that invokes Thunderbird.exe.Recommendations:
For Mozilla Firefox versions prior to 2.0.0.5, update to version 2.0.0.5 or later to resolve the issue.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firefox
Thunderbird