Lucene search

K
cvelistMitreCVELIST:CVE-2007-4040
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2007-4040

2022-10-0316:14:35
mitre
www.cve.org
1
microsoft outlook
argument injection
cross-browser scripting
cve-2007-4040

9.2 High

AI Score

Confidence

High

0.512 Medium

EPSS

Percentile

97.6%

Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670.