CVE-2007-0537: XSS
The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a comment in a title tag, a related issue to CVE-2007-0478.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0537?
CVE-2007-0537 has a moderate severity rating due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2007-0537?
To fix CVE-2007-0537, update to a version of Konqueror that is not vulnerable to this HTML parsing issue.
Which versions of Konqueror are affected by CVE-2007-0537?
CVE-2007-0537 specifically affects Konqueror version 3.5.5.
Can CVE-2007-0537 be exploited remotely?
Yes, CVE-2007-0537 can be exploited by remote attackers to execute cross-site scripting attacks.
What are the consequences of CVE-2007-0537 if exploited?
Exploitation of CVE-2007-0537 can lead to unauthorized script execution in a user's browser, potentially compromising user data.