Описание
Cross-zone scripting vulnerability in Darksky RSS bar for Internet Explorer before 1.29, RSS bar for Sleipnir before 1.29, and RSS bar for unDonut before 1.29 allows remote attackers to bypass Web content zone restrictions via certain script contained in RSS data. NOTE: some of these details are obtained from third party information.
Уязвимые конфигурации
Конфигурация 1Версия до 1.28_release3 (включая)Версия до 1.28_release3 (включая)Версия до 1.28_release3 (включая)
Одно из
cpe:2.3:a:fenrir:darksky_rss_bar:*:*:internet_explorer:*:*:*:*:*
cpe:2.3:a:fenrir:darksky_rss_bar:*:*:sleipnir:*:*:*:*:*
cpe:2.3:a:fenrir:darksky_rss_bar:*:*:undonut:*:*:*:*:*
EPSS
Процентиль: 56%
0.00338
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Cross-zone scripting vulnerability in Darksky RSS bar for Internet Explorer before 1.29, RSS bar for Sleipnir before 1.29, and RSS bar for unDonut before 1.29 allows remote attackers to bypass Web content zone restrictions via certain script contained in RSS data. NOTE: some of these details are obtained from third party information.
EPSS
Процентиль: 56%
0.00338
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other