Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple argument injection vulnerabilities in Mozilla Firefox 2.0.0.5 and 3.0alpha allow remote attackers to execute arbitrary commands via a NULL byte (%00) and shell metacharacters in a (1) mailto, (2) nntp, (3) news, (4) snews, or (5) telnet URI, a similar issue to CVE-2007-3670.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox操作系统操作系统命令注入漏洞
Vulnerability Description
Mozilla Firefox是美国Mozilla基金会的一款开源Web浏览器。 Firefox处理包含特定字符的URL串时存在操作系统命令注入漏洞,远程攻击者可能利用此漏洞在用户系统上执行任意命令。 Firefox没有过滤传送给某些URI的数据,如果向http、https、ftp、gopher、telnet、mailto、news、snews、nttp等协议传送了包含有"%00"字符的URL,就会根据完整URL的扩展名调用FileType处理器而不是ULR协议处理器,然后将URL传送给该文件处理器。远程
CVSS Information
N/A
Vulnerability Type
N/A