Multiple argument injection vulnerabilities in Netscape Navigator 9 allow remote attackers to execute arbitrary commands via a NULL byte (%00) and shell metacharacters in a (1) mailto, (2) nntp, (3) news, (4) snews, or (5) telnet URI, a similar issue to CVE-2007-3670.
2007-07-27T22:30:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | microsoft | windows_2003_server | * | No |
Operating System | microsoft | windows_2003_server | * | No |
Operating System | microsoft | windows_2003_server | * | No |
Operating System | microsoft | windows_2003_server | * | No |
Operating System | microsoft | windows_xp | * | No |
Operating System | microsoft | windows_xp | * | No |
Application | microsoft | internet_explorer | 7 | Yes |
Application | netscape | navigator | 9.0 | Yes |