CVE-2008-0454
Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 25.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title field of a (1) Dailymotion and possibly (2) Metacafe movie in the Skype video gallery, accessible through a search within the "Add video to chat" dialog, aka "videomood XSS."
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 25.20% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- microsoft/internet explorer · skype technologies/skype
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2008-01/0337.html
- http://archives.neohapsis.com/archives/fulldisclosure/2008-01/0363.html
- http://aviv.raffon.net/2008/01/17/SkypeCrosszoneScriptingVulnerability.aspx
- http://share.skype.com/sites/security/2008/01/skype_cross_zone_scripting_vul.html
- http://skype.com/security/skype-sb-2008-001-update1.html
- http://skype.com/security/skype-sb-2008-001.html
- http://www.critical.lt/?opinions/show/1470
- http://www.gnucitizen.org/blog/vulnerabilities-in-skype
- http://www.kb.cert.org/vuls/id/248184US Government Resource
- http://www.securityfocus.com/archive/1/486512/100/0/threaded
- http://www.securityfocus.com/bid/27338
- http://www.vupen.com/english/advisories/2008/0194
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39754
- http://archives.neohapsis.com/archives/fulldisclosure/2008-01/0337.html
- http://archives.neohapsis.com/archives/fulldisclosure/2008-01/0363.html
- http://aviv.raffon.net/2008/01/17/SkypeCrosszoneScriptingVulnerability.aspx
- http://share.skype.com/sites/security/2008/01/skype_cross_zone_scripting_vul.html
- http://skype.com/security/skype-sb-2008-001-update1.html
- http://skype.com/security/skype-sb-2008-001.html
- http://www.critical.lt/?opinions/show/1470
- http://www.gnucitizen.org/blog/vulnerabilities-in-skype
- http://www.kb.cert.org/vuls/id/248184US Government Resource
- http://www.securityfocus.com/archive/1/486512/100/0/threaded
- http://www.securityfocus.com/bid/27338
- http://www.vupen.com/english/advisories/2008/0194
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39754
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.