Vulnerability Name: | CVE-2004-1798 (CCN-14168) | ||||||||
Assigned: | 2004-01-06 | ||||||||
Published: | 2004-01-06 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | RealOne player 6.0.11.868 allows remote attackers to execute arbitrary script in the "My Computer" zone via a Synchronized Multimedia Integration Language (SMIL) presentation with a "file:javascript:" URL, which is executed in the security context of the previously loaded URL, a different vulnerability than CVE-2003-0726. | ||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue Jan 06 2004 - 21:14:13 CST RealNetworks fails to address Cross-Site Scripting in RealOne Player Source: MITRE Type: CNA CVE-2004-1798 Source: CCN Type: SA9584 RealOne Player SMIL Cross-Site Scripting Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 9584 Source: CCN Type: SECTRACK ID: 1008647 RealOne Player Input Validation Flaw Permits Remote Script Execution Source: SECTRACK Type: Exploit, Third Party Advisory, VDB Entry 1008647 Source: CCN Type: US-CERT VU#473902 Multiple Real media players fail to properly validate SMIL files Source: OSVDB Type: Broken Link, Patch 3826 Source: CCN Type: OSVDB ID: 3826 RealOne/RealPlayer SMIL XSS Source: BUGTRAQ Type: Exploit, Third Party Advisory, VDB Entry 20040107 RealNetworks fails to address Cross-Site Scripting in RealOne Player Source: BID Type: Exploit, Patch, Third Party Advisory, VDB Entry 9378 Source: CCN Type: BID-9378 RealOne Player SMIL File Script Execution Variant Vulnerability Source: XF Type: Third Party Advisory, VDB Entry realoneplayer-smil-xss(14168) Source: XF Type: UNKNOWN realoneplayer-smil-xss(14168) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |