2024-11-22 07:15:30 +00:00

105 lines
3.4 KiB
JSON

{
"id": "CVE-2007-3150",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-06-11T19:30:00.000",
"lastModified": "2024-11-21T00:32:31.353",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Google Desktop allows user-assisted remote attackers to execute arbitrary programs via a man-in-the-middle attack that injects JavaScript, a www.google.com search IFRAME, and a META HTTP-EQUIV=\"refresh\" that targets a www.google.com search for a local .exe file, which is displayed in the \"results stored on your computer\" portion of the search results, and when clicked invokes Google Desktop to execute this file."
},
{
"lang": "es",
"value": "Google Desktop permite a atacantes con la intervenci\u00f3n del usuario ejecutar programas de su elecci\u00f3n a trav\u00e9s de un ataque de hombre en el medio (man-in-the-middle) que inyecta JavaScript, un IFRAMe de b\u00fasqueda www.google.com, y un META HTTP-EQUIV=\"refresh\" que hace blanco en una b\u00fasqueda www.google.com para un fichero local .exe, lo cual se muestra en la parte de \"resultados almacenado sobre tu PC (results stored on your computer)\" del resultado de b\u00fasqueda, y cuando al clickar invocamos Google Desktop para ejecutar este fichero."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"baseScore": 9.3,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE"
},
"baseSeverity": "HIGH",
"exploitabilityScore": 8.6,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": true,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:google:desktop:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8CAB8A8E-45AD-4E60-AB59-599506B31BD4"
}
]
}
]
}
],
"references": [
{
"url": "http://ha.ckers.org/blog/20070531/google-desktop-0day/",
"source": "cve@mitre.org"
},
{
"url": "http://ha.ckers.org/google-desktop-0day/",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://osvdb.org/40566",
"source": "cve@mitre.org"
},
{
"url": "http://ha.ckers.org/blog/20070531/google-desktop-0day/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://ha.ckers.org/google-desktop-0day/",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit"
]
},
{
"url": "http://osvdb.org/40566",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}