← Back

CVE-2007-6589

nvd nist
Published: Dec 28, 2007Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 does not update the origin domain when retrieving the inner URL parameter yields an HTTP redirect, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI, a different vulnerability than CVE-2007-5947.

Affected (2)

2 products
Firefox
Seamonkey
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.0.0.9
Up to 1.1.6

Timeline

No history available yet.