Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-3647

Опубликовано: 18 июн. 2013
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

The WebView class in the Cybozu Live application before 2.0.1 for Android allows attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file associated with a file: URL. NOTE: this vulnerability exists because of a CVE-2012-4009 regression.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cybozu:cybozu_live:*:-:*:*:*:android:*:*
Версия до 2.0.0 (включая)
cpe:2.3:a:cybozu:cybozu_live:1.0.4:-:*:*:*:android:*:*

EPSS

Процентиль: 60%
0.00396
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

github
больше 3 лет назад

The WebView class in the Cybozu Live application before 2.0.1 for Android allows attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file associated with a file: URL. NOTE: this vulnerability exists because of a CVE-2012-4009 regression.

EPSS

Процентиль: 60%
0.00396
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-200