PT-2003-1307 · Microsoft · Windows Me
Fozzy
+1
·
Publicado
2003-03-07
·
Atualizado
2018-10-12
·
CVE-2003-0009
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Me
Description
A cross-site scripting (XSS) issue exists in the Help and Support Center, allowing remote attackers to execute arbitrary script in the Local Computer security context. This is achieved via an hcp:// URL with the malicious script in the
topic parameter.Recommendations
For Microsoft Windows Me, consider disabling the Help and Support Center or restricting access to it until a fix is available. Avoid using the
topic parameter in hcp:// URLs to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Windows Me