Cross-site Scripting Vulnerability in Google Desktop by Google
CVE-2007-1085
Currently unrated
Summary
A cross-site scripting (XSS) vulnerability in Google Desktop enables remote attackers to execute arbitrary web scripts or HTML on user systems. This is achieved by exploiting an XSS flaw in google.com that allows attackers to extract the internal web server's signature. By manipulating the 'under' parameter in an Advanced Search, attackers can successfully bypass protective measures, potentially leading to unauthorized access to user systems.
References
EPSS Score
10% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved