PT-2007-5538 · Mozilla · Firefox
Published
2007-08-15
·
Updated
2018-10-15
·
CVE-2007-4357
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions 2.0.0.6 and earlier
Description
The issue allows remote attackers to spoof the contents of the status bar via a link to a
data: URI containing an encoded URL. It's worth noting that the severity of this issue has been disputed, as the intended functionality of the status bar allows it to be modified.Recommendations
For Mozilla Firefox versions 2.0.0.6 and earlier, consider disabling the display of the status bar or restricting links to
data: URis as a temporary workaround until a fix is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Firefox