PT-2005-2202 · Microsoft+1 · Internet Explorer+1
Robert Fly
·
Publicado
2005-04-19
·
Atualizado
2017-07-11
·
CVE-2005-1186
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Musicmatch Jukebox versions 10.00.2047 and earlier
Description
The issue allows systems in the musicmatch.com domain to conduct unauthorized activities due to the addition of the musicmatch.com domain to the Trusted Sites zone in Internet Explorer. This can be exploited using cross-site scripting (XSS) attacks.
Recommendations
For Musicmatch Jukebox versions 10.00.2047 and earlier, consider removing the musicmatch.com domain from the Trusted Sites zone in Internet Explorer as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Internet Explorer
Musicmatch Jukebox