Cross-site Scripting Vulnerability in Google Desktop by Google
CVE-2007-1085

Currently unrated

Key Information:

Vendor
Google
Status
Vendor
CVE Published:
23 February 2007

Summary

A cross-site scripting (XSS) vulnerability in Google Desktop enables remote attackers to execute arbitrary web scripts or HTML on user systems. This is achieved by exploiting an XSS flaw in google.com that allows attackers to extract the internal web server's signature. By manipulating the 'under' parameter in an Advanced Search, attackers can successfully bypass protective measures, potentially leading to unauthorized access to user systems.

References

EPSS Score

10% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.