PT-2005-2202 · Microsoft+1 · Internet Explorer+1

Robert Fly

·

Publicado

2005-04-19

·

Atualizado

2017-07-11

·

CVE-2005-1186

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Musicmatch Jukebox versions 10.00.2047 and earlier
Description The issue allows systems in the musicmatch.com domain to conduct unauthorized activities due to the addition of the musicmatch.com domain to the Trusted Sites zone in Internet Explorer. This can be exploited using cross-site scripting (XSS) attacks.
Recommendations For Musicmatch Jukebox versions 10.00.2047 and earlier, consider removing the musicmatch.com domain from the Trusted Sites zone in Internet Explorer as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-1186

Produtos afetados

Internet Explorer
Musicmatch Jukebox