CVE-2007-4960 describes an argument injection vulnerability in the Linden Lab Second Life secondlife:// protocol handler, affecting Internet Explorer and potentially Firefox. This flaw allows remote attackers to extract sensitive information, including login credentials and software installation details, by manipulating arguments to post them to an arbitrary URL. With a CVSS score of 5.0 (medium severity), the attack requires no authentication and has low complexity, leading to potential information disclosure. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1CPE matchmatch criteria | cpe:2.3:a:linden_lab:second_life:1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.