CVE-2007-1085

medium

Description

Cross-site scripting (XSS) vulnerability in Google Desktop allows remote attackers to bypass protection schemes and inject arbitrary web script or HTML, and possibly gain full access to the system, by using an XSS vulnerability in google.com to extract the signature for the internal web server, then calling the "under" parameter in Advanced Search with the proper signature.

References

http://www.watchfire.com/resources/Overtaking-Google-Desktop.pdf

http://www.securitytracker.com/id?1017686

http://www.securityfocus.com/archive/1/460928/100/0/threaded

http://www.securityfocus.com/archive/1/460735/100/0/threaded

http://www.kb.cert.org/vuls/id/615857

http://securityreason.com/securityalert/2301

http://osvdb.org/33483

Details

Source: Mitre, NVD

Published: 2007-02-23

Updated: 2018-10-16

Risk Information

CVSS v2

Base Score: 7.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Severity: Medium