CVE-2007-4478: XSS
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6.0 and 7 allows user-assisted remote attackers to inject arbitrary web script or HTML in the local zone via a URI, when the document at the associated URL is saved to a local file, which then contains the URI string along with the document's original content.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4478?
CVE-2007-4478 is considered a moderate severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2007-4478?
To mitigate CVE-2007-4478, users should apply the latest security updates for Microsoft Internet Explorer or consider using alternative web browsers.
Which versions of Internet Explorer are affected by CVE-2007-4478?
CVE-2007-4478 specifically affects Microsoft Internet Explorer 6.0 and 7.
What type of vulnerability is CVE-2007-4478?
CVE-2007-4478 is classified as a cross-site scripting (XSS) vulnerability.
Can CVE-2007-4478 be exploited without user assistance?
CVE-2007-4478 requires user assistance to be exploited, as it involves saving a document from a malicious URL.