Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5cf7-xj2f-mmwx

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

RealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation with a URL that references a scripting protocol, which is executed in the security context of the previously loaded URL, as demonstrated using a "javascript:" URL in the area tag.

RealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation with a URL that references a scripting protocol, which is executed in the security context of the previously loaded URL, as demonstrated using a "javascript:" URL in the area tag.

EPSS

Процентиль: 93%
0.09581
Низкий

Связанные уязвимости

nvd
почти 22 года назад

RealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation with a URL that references a scripting protocol, which is executed in the security context of the previously loaded URL, as demonstrated using a "javascript:" URL in the area tag.

EPSS

Процентиль: 93%
0.09581
Низкий