First published: Fri Oct 12 2007(Updated: )
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses single quote characters to delimit a literal string within an XSS sequence, a related issue to CVE-2007-5415.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <=1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5414 is considered a medium severity cross-site scripting (XSS) vulnerability.
The best way to fix CVE-2007-5414 is to upgrade to Mozilla Firefox version 2.0 or later.
CVE-2007-5414 affects Mozilla Firefox versions prior to 2.0, specifically versions 1.8 and lower.
CVE-2007-5414 allows remote attackers to inject arbitrary web scripts or HTML through crafted gopher URIs.
While CVE-2007-5414 affected an older version of Firefox, XSS vulnerabilities are commonly-exploited security issues across various applications.