### [CVE-2017-5124](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5124) ![](https://img.shields.io/static/v1?label=Product&message=Google%20Chrome%20prior%20to%2062.0.3202.62&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Inappropriate%20implementation&color=brighgreen) ### Description Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page. ### POC #### Reference - https://github.com/Bo0oM/CVE-2017-5124 - https://github.com/Bo0oM/CVE-2017-5124 - https://www.reddit.com/r/netsec/comments/7cus2h/chrome_61_uxss_exploit_cve20175124/ - https://www.reddit.com/r/netsec/comments/7cus2h/chrome_61_uxss_exploit_cve20175124/ #### Github - https://github.com/0xR0/uxss-db - https://github.com/ARPSyndicate/cvemon - https://github.com/Bo0oM/CVE-2017-5124 - https://github.com/Metnew/uxss-db - https://github.com/grandDancer/CVE-2017-5124-RCE-0-Day - https://github.com/lnick2023/nicenice - https://github.com/neslinesli93/awesome-stars - https://github.com/qazbnm456/awesome-cve-poc - https://github.com/xbl2022/awesome-hacking-lists - https://github.com/xbl3/awesome-cve-poc_qazbnm456