First published: Fri Oct 12 2007(Updated: )
Cross-site scripting (XSS) vulnerability in Mozilla Firefox 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses '/' (slash) characters to delimit a literal string within an XSS sequence, a related issue to CVE-2007-5414.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5415 has a moderate severity rating due to its potential for cross-site scripting attacks.
To mitigate CVE-2007-5415, it is recommended to update to a version of Mozilla Firefox that is newer than 2.0.
CVE-2007-5415 specifically affects Mozilla Firefox version 2.0.
CVE-2007-5415 allows remote attackers to inject arbitrary web scripts or HTML via a specially crafted gopher URI.
CVE-2007-5415 exploits a vulnerability in Firefox when UTF-7 document content is rendered directly, allowing XSS via slashes in gopher URIs.