First published: Wed Jun 06 2007(Updated: )
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.4 on Windows allows remote attackers to read arbitrary files via ..%5C (dot dot encoded backslash) sequences in a resource:// URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | =2.0.0.2 | |
Mozilla Firefox | =2.0 | |
Mozilla Firefox | =2.0.0.3 | |
Mozilla Firefox | =2.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3072 is considered a high severity vulnerability due to its ability to allow remote attackers to read arbitrary files from the system.
To mitigate CVE-2007-3072, upgrade Mozilla Firefox to version 2.0.0.4 or later as it addresses this vulnerability.
CVE-2007-3072 affects Mozilla Firefox versions 2.0, 2.0.0.1, 2.0.0.2, and 2.0.0.3.
Yes, CVE-2007-3072 can be exploited remotely without any user interaction when a user visits a specially crafted URL.
CVE-2007-3072 enables attackers to access sensitive files on the user's system, potentially leading to information disclosure.