2.6
CVSSv2

CVE-2007-0537

Published: 29/01/2007 Updated: 16/10/2018
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote malicious users to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a comment in a title tag, a related issue to CVE-2007-0478.

Vulnerable Product Search on Vulmon Subscribe to Product

kde konqueror 3.5.5

Vendor Advisories

Jose Avila III and Robert Tasarz discovered that the KDE HTML library did not correctly parse HTML comments inside the “title” tag By tricking a Konqueror user into visiting a malicious website, an attacker could bypass cross-site scripting protections ...