// For flags

CVE-2008-0583

 

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Description and unspecified other metadata fields of a Metacafe movie submitted by Metacafe Pro to the Skype video gallery, accessible through a search within the (1) "Add video to chat" or (2) "Add video to mood" dialog, a different vector than CVE-2008-0454.

Vulnerabilidad de secuencias de comandos en zonas cruzadas en el control web de Internet Explorer en Skype 3.6.0.244 y las versiones anteriores 3.5.x y 3.6.x. En Windows permite que atacantes remotos con la intervención del usuario puedan inyectar secuencias de comandos web o HTMLs de su elección en la Zona de la Máquina Local a través de Description (descripción) y otros campos metadata sin especificar de una película Metacafe enviada por Metacafe Pro a la galería de vídeo de Skype. Lo hace accesible a través de una búsqueda dentro de el diálogo (1) "Add video to chat (Añadir el vídeo al chat)" o (2) "Add video to mood (Añadir vídeo al modo)" , un vector distinto a CVE-2008-0454.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-02-04 CVE Reserved
  • 2008-02-05 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • 2024-11-01 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Skype Technologies
Search vendor "Skype Technologies"
Skype
Search vendor "Skype Technologies" for product "Skype"
3.5
Search vendor "Skype Technologies" for product "Skype" and version "3.5"
-
Affected
Skype Technologies
Search vendor "Skype Technologies"
Skype
Search vendor "Skype Technologies" for product "Skype"
3.6
Search vendor "Skype Technologies" for product "Skype" and version "3.6"
-
Affected
Skype Technologies
Search vendor "Skype Technologies"
Skype
Search vendor "Skype Technologies" for product "Skype"
3.6.216
Search vendor "Skype Technologies" for product "Skype" and version "3.6.216"
-
Affected
Skype Technologies
Search vendor "Skype Technologies"
Skype
Search vendor "Skype Technologies" for product "Skype"
3.6.244
Search vendor "Skype Technologies" for product "Skype" and version "3.6.244"
-
Affected