CVE Database
/

CVE-2007-3670

Back to search

CVE-2007-3670

Published: Jul 10, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a (1) FirefoxURL or (2) FirefoxHTML URI, which are inserted into the command line that is created when invoking firefox.exe. NOTE: it has been debated as to whether the issue is in Internet Explorer or Firefox. As of 20070711, it is CVE's opinion that IE appears to be failing to properly delimit the URL argument when invoking Firefox, and this issue could arise with other protocol handlers in IE as well. However, Mozilla has stated that it will address the issue with a "defense in depth" fix that will "prevent IE from sending Firefox malicious data."

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2007-2473
vdb-entry
x_refsource_VUPEN
USN-503-1
vendor-advisory
x_refsource_UBUNTU
1018360
vdb-entry
x_refsource_SECTRACK
1018351
vdb-entry
x_refsource_SECTRACK
HPSBUX02156
vendor-advisory
x_refsource_HP
HPSBUX02153
vendor-advisory
x_refsource_HP
MDKSA-2007:152
vendor-advisory
x_refsource_MANDRIVA
25984
third-party-advisory
x_refsource_SECUNIA
TA07-199A
third-party-advisory
x_refsource_CERT
28179
third-party-advisory
x_refsource_SECUNIA
24837
vdb-entry
x_refsource_BID
26216
third-party-advisory
x_refsource_SECUNIA
SSRT061236
vendor-advisory
x_refsource_HP
ADV-2007-2565
vdb-entry
x_refsource_VUPEN
26149
third-party-advisory
x_refsource_SECUNIA
ADV-2008-0082
vdb-entry
x_refsource_VUPEN
38017
vdb-entry
x_refsource_OSVDB
VU#358017
third-party-advisory
x_refsource_CERT-VN
ADV-2007-4272
vdb-entry
x_refsource_VUPEN
SUSE-SA:2007:049
vendor-advisory
x_refsource_SUSE
SSRT061181
vendor-advisory
x_refsource_HP
20070710 Internet Explorer 0day exploit
mailing-list
x_refsource_FULLDISC
26258
third-party-advisory
x_refsource_SECUNIA
28363
third-party-advisory
x_refsource_SECUNIA
20070710 Internet Explorer 0day exploit
mailing-list
x_refsource_BUGTRAQ
26271
third-party-advisory
x_refsource_SECUNIA
26204
third-party-advisory
x_refsource_SECUNIA
26572
third-party-advisory
x_refsource_SECUNIA
26096
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now