Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-0454

Опубликовано: 25 янв. 2008
Источник: nvd
CVSS2: 9.3
EPSS Средний

Описание

Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title field of a (1) Dailymotion and possibly (2) Metacafe movie in the Skype video gallery, accessible through a search within the "Add video to chat" dialog, aka "videomood XSS."

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

Одно из

cpe:2.3:a:microsoft:internet_explorer:*:*:*:*:*:*:*:*
cpe:2.3:a:skype_technologies:skype:*:*:*:*:*:*:*:*
Версия до 3.6.0.244 (включая)
cpe:2.3:a:skype_technologies:skype:3.5:*:*:*:*:*:*:*
cpe:2.3:a:skype_technologies:skype:3.6:*:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.41318
Средний

9.3 Critical

CVSS2

Дефекты

CWE-79

Связанные уязвимости

github
почти 4 года назад

Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title field of a (1) Dailymotion and possibly (2) Metacafe movie in the Skype video gallery, accessible through a search within the "Add video to chat" dialog, aka "videomood XSS."

EPSS

Процентиль: 97%
0.41318
Средний

9.3 Critical

CVSS2

Дефекты

CWE-79