Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2004-2475

Опубликовано: 31 дек. 2004
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protocol does not cross privilege boundaries, since it is not allowed in the Internet Zone. Thus this might not be a vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:google:toolbar:1.1.41:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.42:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.43:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.44:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.45:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.47:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.48:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.49:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.53:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.54:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.55:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.56:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.57:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.58:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.59:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:1.1.60:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:2.0.114.1:*:*:*:*:*:*:*
cpe:2.3:a:google:toolbar:2.0.114.1:*:big_en_ggld:*:*:*:*:*

EPSS

Процентиль: 75%
0.00855
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protocol does not cross privilege boundaries, since it is not allowed in the Internet Zone. Thus this might not be a vulnerability.

EPSS

Процентиль: 75%
0.00855
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other