Lucene search

K
cveMitreCVE-2008-7037
HistoryAug 24, 2009 - 10:30 a.m.

CVE-2008-7037

2009-08-2410:30:01
CWE-20
mitre
web.nvd.nist.gov
22
cve-2008-7037
itn news gadget
windows vista
remote code execution
security vulnerability

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

High

EPSS

0.002

Percentile

51.4%

The Sidebar gadget in ITN News Gadget (aka ITN Hub Gadget) 1.06 for Windows Vista, and possibly other versions before 1.23, allows remote web servers or man-in-the-middle attackers to execute arbitrary commands via script in a short_title response.

Affected configurations

Nvd
Node
itnitn_news_gadgetMatch1.06
AND
microsoftwindows_vista
VendorProductVersionCPE
itnitn_news_gadget1.06cpe:2.3:a:itn:itn_news_gadget:1.06:*:*:*:*:*:*:*
microsoftwindows_vista*cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

High

EPSS

0.002

Percentile

51.4%

Related for CVE-2008-7037