Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-3150

Опубликовано: 11 июн. 2007
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

Google Desktop allows user-assisted remote attackers to execute arbitrary programs via a man-in-the-middle attack that injects JavaScript, a www.google.com search IFRAME, and a META HTTP-EQUIV="refresh" that targets a www.google.com search for a local .exe file, which is displayed in the "results stored on your computer" portion of the search results, and when clicked invokes Google Desktop to execute this file.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:google:desktop:*:*:*:*:*:*:*:*

EPSS

Процентиль: 77%
0.01017
Низкий

9.3 Critical

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Google Desktop allows user-assisted remote attackers to execute arbitrary programs via a man-in-the-middle attack that injects JavaScript, a www.google.com search IFRAME, and a META HTTP-EQUIV="refresh" that targets a www.google.com search for a local .exe file, which is displayed in the "results stored on your computer" portion of the search results, and when clicked invokes Google Desktop to execute this file.

EPSS

Процентиль: 77%
0.01017
Низкий

9.3 Critical

CVSS2

Дефекты

NVD-CWE-Other