CVE-2007-5947: XSS
The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI.
Affected Software
Event History
Frequently Asked Questions
Which versions are affected?
Mozilla Firefox versions before 2.0.0.10 and SeaMonkey versions before 1.1.7 are affected.
What does an attacker need to exploit this issue?
A remote attacker can exploit the issue by using a jar: URI. No authentication is required, but the attack complexity is rated medium.
What is the security impact?
The vulnerability enables cross-site scripting because HTML content inside a JAR archive can be treated as having the same origin as the inner URL. The listed impact is integrity-only; confidentiality and availability impacts are not listed.