CVE-2007-3089Cross-site Scripting in Mozilla Firefox

Severity
4.3MEDIUMNVD
EPSS
25.3%
top 3.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 6
Latest updateMay 3

Description

Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

NVDmozilla/firefox2.0.0.4+41
NVDmozilla/thunderbird2.0.0.5

🔴Vulnerability Details

2
GHSA
GHSA-w739-3fq5-fgvp: Mozilla Firefox before 22022-05-03
GHSA
GHSA-6p6h-7mm4-6mhv: Mozilla Firefox 22022-05-01

📋Vendor Advisories

3
Red Hat
about: blank windows2007-07-31
Ubuntu
Firefox vulnerabilities2007-07-20
Red Hat
security flaw2007-06-04

💬Community

2
Bugzilla
CVE-2007-3089 security flaw2018-08-16
Bugzilla
CVE-2007-3089 various flaws in mozilla products (CVE-2007-3734 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3656 CVE-2007-3738)2007-07-17