CVE-2008-0582
Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.1 through 3.6.0.244 on Windows allows remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Full Name field of a reviewer of a…
Does this matter?
Lower severity and a low EPSS score (1.21%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.1 through 3.6.0.244 on Windows allows remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Full Name field of a reviewer of a business item entry, accessible through (1) the SkypeFind dialog and (2) a skype:?skypefind URI for the skype: URI handler.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.21% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- skype technologies/skype
- Source
- cve@mitre.org
References
- http://aviv.raffon.net/2008/01/31/AttackersCanSkypeFindYou.aspx
- http://www.kb.cert.org/vuls/id/794236US Government Resource
- http://www.securityfocus.com/archive/1/487370/100/0/threaded
- http://www.securityfocus.com/bid/27338
- http://aviv.raffon.net/2008/01/31/AttackersCanSkypeFindYou.aspx
- http://www.kb.cert.org/vuls/id/794236US Government Resource
- http://www.securityfocus.com/archive/1/487370/100/0/threaded
- http://www.securityfocus.com/bid/27338
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.