PT-2004-2698 · Realnetworks · Realone Player
Publicado
2004-12-31
·
Atualizado
2017-07-11
·
CVE-2004-1798
CVSS v2.0
5.1
Média
| Vetor | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
RealOne player version 6.0.11.868
Description
The issue allows remote attackers to execute arbitrary script in the "My Computer" zone. This is achieved via a Synchronized Multimedia Integration Language (SMIL) presentation with a "file:javascript:" URL. The script is executed in the security context of the previously loaded URL.
Recommendations
For RealOne player version 6.0.11.868, consider disabling the execution of SMIL presentations with "file:javascript:" URLs as a temporary workaround until a patch is available. Restrict access to SMIL files to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Realone Player