CVE-2007-6589

Mozilla Firefox <2.0.0.10 & SeaMonkey <1.1.7 - XSS

Title source: llm
STIX 2.1

Description

The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 does not update the origin domain when retrieving the inner URL parameter yields an HTTP redirect, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI, a different vulnerability than CVE-2007-5947.

References (8)

Core 8
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=403331
Various Sources x_refsource_misc
http://blog.beford.org/?p=8
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0083
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/43477
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6033
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=369814

Scores

EPSS 0.0107
EPSS Percentile 61.1%

Details

CWE
CWE-79
Status published
Products (2)
mozilla/firefox < 2.0.0.9
mozilla/seamonkey < 1.1.6
Published Dec 28, 2007
Tracked Since Feb 18, 2026