CVE-2007-5960Path Traversal in Mozilla Seamonkey

Severity
4.3MEDIUMNVD
EPSS
1.3%
top 20.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 26
Latest updateMay 1

Description

Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer headers and bypass Referer-based CSRF protection schemes by setting window.location and using a modal alert dialog that causes the wrong Referer to be sent.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDmozilla/firefox48 versions+47

🔴Vulnerability Details

1
GHSA
GHSA-9vw2-7m33-r6hw: Mozilla Firefox before 22022-05-01

📋Vendor Advisories

3
Ubuntu
Firefox regression2007-12-04
Red Hat
Mozilla Cross-site Request Forgery flaw2007-11-26
Ubuntu
Firefox vulnerabilities2007-11-26

💬Community

1
Bugzilla
CVE-2007-5960 Mozilla Cross-site Request Forgery flaw2007-11-21
CVE-2007-5960 — Path Traversal in Mozilla Seamonkey | cvebase