First published: Tue Feb 05 2008(Updated: )
Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.1 through 3.6.0.244 on Windows allows remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Full Name field of a reviewer of a business item entry, accessible through (1) the SkypeFind dialog and (2) a skype:?skypefind URI for the skype: URI handler.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Skype | =3.1 | |
Microsoft Skype | =3.2 | |
Microsoft Skype | =3.5 | |
Microsoft Skype | =3.6 | |
Microsoft Skype | =3.6.0.244 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0582 has a moderate severity rating due to its potential for cross-zone scripting attacks.
To fix CVE-2008-0582, update Skype to a version that is not vulnerable, specifically later than 3.6.0.244.
CVE-2008-0582 affects Skype versions 3.1 through 3.6.0.244.
Users of affected Skype versions could have their systems exploited to execute arbitrary web scripts or HTML.
Yes, CVE-2008-0582 is a remote vulnerability that allows attackers to inject scripts through manipulated inputs.