PT-2005-2202 · Microsoft+1 · Internet Explorer+1

Robert Fly

·

Published

2005-04-19

·

Updated

2017-07-11

·

CVE-2005-1186

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Musicmatch Jukebox versions 10.00.2047 and earlier
Description The issue allows systems in the musicmatch.com domain to conduct unauthorized activities due to the addition of the musicmatch.com domain to the Trusted Sites zone in Internet Explorer. This can be exploited using cross-site scripting (XSS) attacks.
Recommendations For Musicmatch Jukebox versions 10.00.2047 and earlier, consider removing the musicmatch.com domain from the Trusted Sites zone in Internet Explorer as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1186

Affected Products

Internet Explorer
Musicmatch Jukebox