CVE-2008-0583
published 2008-02-05CVE-2008-0583: Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.06%
79.0th percentile
Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Description and unspecified other metadata fields of a Metacafe movie submitted by Metacafe Pro to the Skype video gallery, accessible through a search within the (1) "Add video to chat" or (2) "Add video to mood" dialog, a different vector than CVE-2008-0454.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| skype_technologies | skype | — | — |
| skype_technologies | skype | — | — |
| skype_technologies | skype | — | — |
| skype_technologies | skype | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
http://aviv.raffon.net/2008/01/22/NoMoreVideosForYouComeBackWhenPatchAvailable.aspxhttp://skype.com/security/skype-sb-2008-001-update1.htmhttp://www.kb.cert.org/vuls/id/794236http://www.securityfocus.com/bid/27338https://exchange.xforce.ibmcloud.com/vulnerabilities/39754http://aviv.raffon.net/2008/01/22/NoMoreVideosForYouComeBackWhenPatchAvailable.aspxhttp://skype.com/security/skype-sb-2008-001-update1.htmhttp://www.kb.cert.org/vuls/id/794236http://www.securityfocus.com/bid/27338https://exchange.xforce.ibmcloud.com/vulnerabilities/39754
2008-02-05
Published