4.3
CVSSv2

CVE-2007-6589

Published: 28/12/2007 Updated: 29/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The jar protocol handler in Mozilla Firefox prior to 2.0.0.10 and SeaMonkey prior to 1.1.7 does not update the origin domain when retrieving the inner URL parameter yields an HTTP redirect, which allows remote malicious users to conduct cross-site scripting (XSS) attacks via a jar: URI, a different vulnerability than CVE-2007-5947.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

mozilla seamonkey