CVE-2007-1085
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 11%
from disclosure to weapon0 days
Published on NVDFeb 23
1st PoCFeb 21
exploitation probability
11%top 5% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Cross-site scripting (XSS) vulnerability in Google Desktop allows remote attackers to bypass protection schemes and inject arbitrary web script or HTML, and possibly gain full access to the system, by using an XSS vulnerability in google.com to extract the signature for the internal web server, then calling the "under" parameter in Advanced Search with the proper signature.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/29623⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://osvdb.org/33483http://securityreason.com/securityalert/2301http://www.kb.cert.org/vuls/id/615857http://www.securityfocus.com/archive/1/460735/100/0/threadedhttp://www.securityfocus.com/archive/1/460928/100/0/threadedhttp://www.securityfocus.com/bid/22650http://www.securitytracker.com/id?1017686http://www.watchfire.com/resources/Overtaking-Google-Desktop.pdf