Loading
Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670.
Use CWE-79, Mozilla vendor hub and Mozilla product page to widen CVE-2007-4039 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2007-1794, CVE-2005-3896 and CVE-2006-0292 for nearby disclosures in the same product family.