6.8

CVE-2005-1186

Musicmatch Jukebox 10.00.2047 and earlier adds the musicmatch.com domain to the Trusted Sites zone in Internet Explorer, which allows systems in the domain to conduct unauthorized activities, as demonstrated using cross-site scripting (XSS) attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MusicmatchJukebox Version <= 10.00.2047
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.12% 0.618
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://securitytracker.com/id?1013718
Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/20129
http://seclists.org/lists/bugtraq/2005/Apr/0212.html
Patch
http://www.hyperdose.com/advisories/H2005-04.txt
Patch