// For flags

CVE-2007-4224

URL spoof in address bar

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar by calling setInterval with a small interval and changing the window.location property.

KDE Konqueror 3.5.7 permite a atacantes remotos suplantar la barra de direcciones URL llamando al setInterval con un intervalo pequeño y cambiando la propiedad window.location.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-08-08 CVE Reserved
  • 2007-08-08 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-59: Improper Link Resolution Before File Access ('Link Following')
CAPEC
References (32)
URL Tag Source
http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065101.html Mailing List
http://secunia.com/advisories/26351 Third Party Advisory
http://secunia.com/advisories/26612 Third Party Advisory
http://secunia.com/advisories/26690 Third Party Advisory
http://secunia.com/advisories/26720 Third Party Advisory
http://secunia.com/advisories/27089 Third Party Advisory
http://secunia.com/advisories/27090 Third Party Advisory
http://secunia.com/advisories/27096 Third Party Advisory
http://secunia.com/advisories/27106 Third Party Advisory
http://secunia.com/advisories/27108 Third Party Advisory
http://secunia.com/advisories/27271 Third Party Advisory
http://securityreason.com/securityalert/2982 Third Party Advisory
http://securitytracker.com/id?1018579 Vdb Entry
http://www.kde.org/info/security/advisory-20070816-1.txt X_refsource_confirm
http://www.securityfocus.com/archive/1/475689/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/475730/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/475731/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/475763/100/0/threaded Mailing List
http://www.securityfocus.com/bid/25219 Vdb Entry
http://www.vupen.com/english/advisories/2007/2807 Vdb Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/35828 Vdb Entry
https://issues.rpath.com/browse/RPL-1615 X_refsource_confirm
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9879 Signature
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Kde
Search vendor "Kde"
Konqueror
Search vendor "Kde" for product "Konqueror"
3.5.7
Search vendor "Kde" for product "Konqueror" and version "3.5.7"
-
Affected