HIGH
Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Netscape installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a -chrome argument to the navigatorurl URI, which are inserted into the command line that is created when invoking netscape.exe, a related issue to CVE-2007-3670
Published Jul 21, 2007
9.3
HIGHCVSS 2.0
EPSS 13.63%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.