CVE-2007-6589
N/A
N/A
Summary
The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 does not update the origin domain when retrieving the inner URL parameter yields an HTTP redirect, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI, a different vulnerability than CVE-2007-5947.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- https://bugzilla.mozilla.org/show_bug.cgi?id=403331
- http://www.mozilla.org/security/announce/2007/mfsa2007-37.html
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742
- http://blog.beford.org/?p=8
- http://www.vupen.com/english/advisories/2008/0083
- http://osvdb.org/43477
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6033
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742
- https://bugzilla.mozilla.org/show_bug.cgi?id=369814
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=403331
- http://www.mozilla.org/security/announce/2007/mfsa2007-37.html
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742
- http://blog.beford.org/?p=8
- http://www.vupen.com/english/advisories/2008/0083
- http://osvdb.org/43477
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6033
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742
- https://bugzilla.mozilla.org/show_bug.cgi?id=369814
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.