CVE-2007-3072
HIGH 7.1EPSS 1.6%
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.4 on Windows allows remote attackers to read arbitrary files via ..%5C (dot dot encoded backslash) sequences in a resource:// URI.
- CVSS v2.0
- 7.1 HIGH
AV:N/AC:M/Au:N/C:C/I:N/A:N - EPSS
- 1.58% chance of exploitation in the next 30 days, 74th percentile
- Published
- 2007-06-06
- Updated
- 2024-08-07
Proof-of-concept exploits (2)
- http://ha.ckers.org/blog/20070516/read-firefox-settings-poc/
- http://ha.ckers.org/blog/20070516/read-firefox-settings-poc/#comment-35888