6.8
CVSSv2

CVE-2007-1564

Published: 21/03/2007 Updated: 11/10/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.

Vulnerable Product Search on Vulmon Subscribe to Product

kde konqueror 3.5.5

Vendor Advisories

It was discovered that Konqueror did not correctly handle iframes from JavaScript If a user were tricked into visiting a malicious website, Konqueror could crash, resulting in a denial of service (CVE-2007-1308) ...

Exploits

source: wwwsecurityfocuscom/bid/23091/info KDE Konqueror is prone to a vulnerability that may allow attackers to obtain potentially sensitive information A successful exploit of this issue would cause the affected application to connect to arbitrary TCP ports and potentially reveal sensitive information about services that are running o ...