mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-12 13:31:34 +02:00
18 lines
973 B
Markdown
18 lines
973 B
Markdown
### [CVE-2007-3844](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3844)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an about:blank document loaded by chrome via (a) the window.open function or (b) a content.location assignment, aka "Cross Context Scripting." NOTE: this issue is caused by a CVE-2007-3089 regression.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9493
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|