CVE-2007-6640: Medium severity Sourceforge Creammonkey vulnerability
Creammonkey 0.9 through 1.1 and GreaseKit 1.2 through 1.3 does not properly prevent access to dangerous functions, which allows remote attackers to read the configuration, modify the configuration, or send an HTTP request via the (1) GMaddStyle, (2) GMlog, (3) GMopenInTab, (4) GMsetValue, (5) GMgetValue, or (6) GMxmlhttpRequest function within a web page on which a userscript is configured.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6640?
CVE-2007-6640 has a moderate severity level due to its potential for unauthorized access to sensitive functions.
How do I fix CVE-2007-6640?
To fix CVE-2007-6640, upgrade to the latest versions of Creammonkey or GreaseKit that have addressed this vulnerability.
What types of attacks are possible with CVE-2007-6640?
CVE-2007-6640 allows remote attackers to read and modify configuration settings and send HTTP requests, which can lead to exploitation of the software.
Which versions of Creammonkey are affected by CVE-2007-6640?
Creammonkey versions 0.9 to 1.1 are affected by CVE-2007-6640.
Which versions of GreaseKit are affected by CVE-2007-6640?
GreaseKit versions 1.2 to 1.3 are affected by CVE-2007-6640.