First published: Mon Jan 29 2007(Updated: )
The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a comment in a title tag, a related issue to CVE-2007-0478.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Konqueror | =3.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0537 has a moderate severity rating due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2007-0537, update to a version of Konqueror that is not vulnerable to this HTML parsing issue.
CVE-2007-0537 specifically affects Konqueror version 3.5.5.
Yes, CVE-2007-0537 can be exploited by remote attackers to execute cross-site scripting attacks.
Exploitation of CVE-2007-0537 can lead to unauthorized script execution in a user's browser, potentially compromising user data.