VulnerabilityModified
CVE-2013-6237
The ISL Desktop plugin for Windows before 1.4.7 for ISL Light 3.5.4 and earlier allows remote authenticated users to obtain sensitive information by pasting the clipboard contents that have been copied by another user in the session.
LOW 3.5EPSS 1.69%
Does this matter?
Lower severity and a low EPSS score (1.69%). Track it; it rarely justifies an emergency change on its own.
Description
The ISL Desktop plugin for Windows before 1.4.7 for ISL Light 3.5.4 and earlier allows remote authenticated users to obtain sensitive information by pasting the clipboard contents that have been copied by another user in the session.
- CVSS 2.0
- 3.5 LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
- EPSS
- 1.69% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- islonline/isl desktop plugin · islonline/isl light
- Source
- cve@mitre.org
References
- http://osvdb.org/100512
- http://packetstormsecurity.com/files/124274/ISL-Light-Desktop-3.5.4-Information-Disclosure.htmlExploit
- http://seclists.org/fulldisclosure/2013/Dec/14Exploit
- http://www.islonline.com/help/isl-releases-info/any/manual/?2013-11-29-rel-info-isl-light-desktop-plugin-1-4-7-win.htmPatch
- http://www.securityfocus.com/bid/64050
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89399
- http://osvdb.org/100512
- http://packetstormsecurity.com/files/124274/ISL-Light-Desktop-3.5.4-Information-Disclosure.htmlExploit
- http://seclists.org/fulldisclosure/2013/Dec/14Exploit
- http://www.islonline.com/help/isl-releases-info/any/manual/?2013-11-29-rel-info-isl-light-desktop-plugin-1-4-7-win.htmPatch
- http://www.securityfocus.com/bid/64050
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89399
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.