vendor:
QuickTime Player
by:
LMH
7.5
CVSS
HIGH
Arbitrary Script Execution
94
CWE
Product Name: QuickTime Player
Affected Version From: QuickTime 7.1.3
Affected Version To: QuickTime 7.1.3
Patch Exists: YES
Related CWE: N/A
CPE: a:apple:quicktime_player
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2007
Apple QuickTime Plug-in Arbitrary Script Execution Vulnerability
Apple QuickTime plug-in is prone to an arbitrary-script-execution weakness when executing QuickTime Media Link files (.qtl). An attacker can exploit this issue to execute arbitrary script code in the context of the affected application and load local content in a user's browser. Although this weakness doesn't pose any direct security threat by itself, an attacker may use it to aid in further attacks.
Mitigation:
Update to the latest version of QuickTime.