Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qgvq-x96v-cf8x

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

RealOne player 6.0.11.868 allows remote attackers to execute arbitrary script in the "My Computer" zone via a Synchronized Multimedia Integration Language (SMIL) presentation with a "file:javascript:" URL, which is executed in the security context of the previously loaded URL, a different vulnerability than CVE-2003-0726.

RealOne player 6.0.11.868 allows remote attackers to execute arbitrary script in the "My Computer" zone via a Synchronized Multimedia Integration Language (SMIL) presentation with a "file:javascript:" URL, which is executed in the security context of the previously loaded URL, a different vulnerability than CVE-2003-0726.

EPSS

Процентиль: 84%
0.02149
Низкий

Связанные уязвимости

nvd
больше 20 лет назад

RealOne player 6.0.11.868 allows remote attackers to execute arbitrary script in the "My Computer" zone via a Synchronized Multimedia Integration Language (SMIL) presentation with a "file:javascript:" URL, which is executed in the security context of the previously loaded URL, a different vulnerability than CVE-2003-0726.

EPSS

Процентиль: 84%
0.02149
Низкий