PT-2007-4433 · Google · Google Desktop

Publicado

2007-06-11

·

Atualizado

2008-11-15

·

CVE-2007-3150

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Google Desktop (affected versions not specified)
Description: The issue allows remote attackers to execute arbitrary programs via a man-in-the-middle attack. This attack involves injecting JavaScript, a www.google.com search IFRAME, and a META HTTP-EQUIV="refresh" that targets a www.google.com search for a local .exe file. The .exe file is displayed in the search results and, when clicked, invokes Google Desktop to execute the file.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-3150

Produtos afetados

Google Desktop