HTTP: Multiple Browser URI Handlers Command Injection Vulnerabilities

This signature detects an attempt to leverage a known vulnerability in the way that some Microsoft Windows based software handles certain malformed URLs. An attacker can use a specially crafted URL to execute arbitrary commands on the affected system. Note that only Windows XP and Windows 2003 systems with Internet Explorer 7 are affected.

Extended Description

Multiple browsers are prone to vulnerabilities that let attackers inject commands through various protocol handlers. Exploiting these issues allows remote attackers to pass and execute arbitrary commands and arguments through processes such as 'cmd.exe' by employing various URI handlers. An attacker can exploit these issues to carry out various attacks by executing arbitrary commands on a vulnerable computer. Exploiting these issues would permit remote attackers to influence command options that can be called through protocol handlers and to execute commands with the privileges of a user running the application. Successful attacks may result in a variety of consequences, including remote unauthorized access. Mozilla Firefox 2.0.0.5, 3.0a6 and Netscape Navigator 9 are reported vulnerable to these issues. Other versions of these browsers and other vendors' browsers may also be affected.

Affected Products

Mozilla thunderbird

Short Name
HTTP:STC:URI-INJ
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Browser CVE-2007-3896 Command Handlers Injection Multiple URI Vulnerabilities bid:25053 bid:25945
Release Date
10/11/2007
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3697
False Positive
Unknown
Vendors

Suse

Sun

Rpath

Mozilla

Turbolinux

Debian

Slackware

Ubuntu

Mandriva

Foresight_linux

Netscape

CVSS Score

9.3

Found a potential security threat?