// For flags

CVE-2007-6640

 

Severity Score

6.4
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Creammonkey 0.9 through 1.1 and GreaseKit 1.2 through 1.3 does not properly prevent access to dangerous functions, which allows remote attackers to read the configuration, modify the configuration, or send an HTTP request via the (1) GM_addStyle, (2) GM_log, (3) GM_openInTab, (4) GM_setValue, (5) GM_getValue, or (6) GM_xmlhttpRequest function within a web page on which a userscript is configured.

Creammonkey 0.9 hasta 1.1 y GreaseKit 1.2 hasta v1.3 no evita apropiadamente el acceso a funciones peligrosas, lo cual permite a atacantes remotos leer la configuración, modificarla, ó enviar una petición HTTP mediante la función (1) GM_addStyle, (2) GM_log, (3) GM_openInTab, (4) GM_setValue, (5) GM_getValue, ó (6) GM_xmlhttpRequest sin una página web en la cual el script de usuario sea configurado.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-01-03 CVE Reserved
  • 2008-01-04 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-11-07 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sourceforge
Search vendor "Sourceforge"
Creammonkey
Search vendor "Sourceforge" for product "Creammonkey"
0.9
Search vendor "Sourceforge" for product "Creammonkey" and version "0.9"
-
Affected
Sourceforge
Search vendor "Sourceforge"
Creammonkey
Search vendor "Sourceforge" for product "Creammonkey"
1.0
Search vendor "Sourceforge" for product "Creammonkey" and version "1.0"
-
Affected
Sourceforge
Search vendor "Sourceforge"
Creammonkey
Search vendor "Sourceforge" for product "Creammonkey"
1.1
Search vendor "Sourceforge" for product "Creammonkey" and version "1.1"
-
Affected
Sourceforge
Search vendor "Sourceforge"
Greasekit
Search vendor "Sourceforge" for product "Greasekit"
1.2
Search vendor "Sourceforge" for product "Greasekit" and version "1.2"
-
Affected
Sourceforge
Search vendor "Sourceforge"
Greasekit
Search vendor "Sourceforge" for product "Greasekit"
1.3
Search vendor "Sourceforge" for product "Greasekit" and version "1.3"
-
Affected