CVE-2007-0706
Summary
| CVE | CVE-2007-0706 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-02-04 00:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Cross-zone scripting vulnerability in Darksky RSS bar for Internet Explorer before 1.29, RSS bar for Sleipnir before 1.29, and RSS bar for unDonut before 1.29 allows remote attackers to bypass Web content zone restrictions via certain script contained in RSS data. NOTE: some of these details are obtained from third party information. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fenrir | Darksky Rss Bar | All | All | internet_explorer | All |
| Application | Fenrir | Darksky Rss Bar | All | All | sleipnir | All |
| Application | Fenrir | Darksky Rss Bar | All | All | undonut | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| JVN#93700808: Sleipnir の RSSバーにおけるセキュリティゾーンの扱いに関する脆弱性 | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Sleipnir におけるセキュリティゾーンの扱いに関する脆弱性 | af854a3a-2127-422b-91ae-364da2661108 | www.fenrir.co.jp | |
| JVN:JVN#93700808 | MITRE | jvn.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.