vendor:
RealOne Player
by:
DigitalPranksters.com
7.5
CVSS
HIGH
Script Embedded in SMIL Presentations
95
CWE
Product Name: RealOne Player
Affected Version From: RealOne Player for Microsoft Windows operating systems
Affected Version To: RealOne Player for Microsoft Windows operating systems
Patch Exists: NO
Related CWE: N/A
CPE: a:realnetworks:realone_player
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows
2003
Real Networks RealOne Player Vulnerability
Real Networks has reported a vulnerability in RealOne Player. Script embedded in SMIL presentations may be executed in the context of a domain that is specified by an attacker. This could allow for theft of cookie-based authentication credentials or other attacks. This vulnerability could also be exploited to execute script code in the context of the My Computer Zone, which could lead to installation and execution of malicious code on the client systems.
Mitigation:
Users should avoid visiting untrusted websites and should not open any suspicious SMIL files.